{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/rodauth/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rodauth:rodauth:*:*:*:*:*:ruby:*:*"],"_cs_cves":[{"cvss":8.7,"id":"CVE-2026-82466"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Rodauth (\u003c 2.46.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Rodauth"],"content_html":"\u003cp\u003eRodauth, an authentication framework for Ruby applications, contains a critical authentication bypass vulnerability (CVE-2026-82466) in the webauthn_login route. The flaw affects all versions prior to 2.46.0. An attacker who is already authenticated as a low-privileged user can exploit this vulnerability to impersonate any other account within the application.\u003c/p\u003e\n\u003cp\u003eThe issue arises from flawed account resolution logic within the WebAuthn authentication flow. Instead of enforcing a strict binding between the provided WebAuthn credential and the intended target account, the application incorrectly falls back to session-based identifiers. This behavior allows an attacker to complete the authentication process for a different user without possessing their valid credentials. This vulnerability poses a significant risk to the integrity and confidentiality of user accounts in applications relying on Rodauth for WebAuthn-based authentication.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full account takeover, enabling unauthorized access to any user profile, associated private data, and administrative functions. The scope of impact is limited to applications utilizing the Rodauth framework with the webauthn_login route enabled.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Rodauth framework to version 2.46.0 or later to apply the security patch for CVE-2026-82466.\u003c/li\u003e\n\u003cli\u003eReview application access logs for an unusual frequency of WebAuthn authentication successes by users that do not correlate with expected session activity.\u003c/li\u003e\n\u003cli\u003eAudit custom authentication logic that integrates with Rodauth to ensure credential binding is strictly validated server-side.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-29T17:41:01Z","date_published":"2026-08-29T17:41:01Z","id":"https://feed.craftedsignal.io/briefs/2026-08-rodauth-auth-bypass/","summary":"Rodauth versions prior to 2.46.0 contain an authentication bypass vulnerability in the webauthn_login route, allowing attackers to impersonate arbitrary users via improper account resolution.","title":"Authentication Bypass in Rodauth WebAuthn Login","url":"https://feed.craftedsignal.io/briefs/2026-08-rodauth-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Rodauth","version":"https://jsonfeed.org/version/1.1"}