Product
Rodauth versions prior to 2.46.0 contain an authentication bypass vulnerability in the webauthn_login route, allowing attackers to impersonate arbitrary users via improper account resolution.