Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-82466: Rodauth login lets logged‑in users impersonate other accounts

CVE-2026-82466 · published 5 days ago
Summary

The Rodauth sign‑in feature allows a user who is already logged in to trick the system into acting as any other user. This happens because the software checks the wrong identifier when confirming a security key login. Update Rodauth to version 2.46.0 or later to fix the issue.

What to do
  • Update jeremyevans rodauth to version 2.46.0 or later.
Affected software
Ecosystem VendorProductAffected versions
jeremyevans rodauth < 2.46.0
Debian:14 debian ruby-rodauth All versions
Original advisory text
Rodauth before 2.46.0 Authentication Bypass via webauthn_login
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account identifiers instead of validating the credential binding to complete authentication as arbitrary users.
Severity
9.4 Critical
CVSS 3.1: 8.7 (NVD)
CVSS 4.0: 9.4 (NVD)
CVSS 3.1: 8.7 (OSV)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published29 Aug 2026
Updated2 Sep 2026
First seen29 Aug 2026
Sources
CVE-2026-82466 · MITRE
Monitor software like this
Free during beta