Junglewise Threat Intelligence

CVE-2026-82466: Rodauth authentication bypass in webauthn_login

CVE-2026-82466 · Severity: high · CVSS 8.7 · Published 2026-08-29

Technologies: Jeremy Evans Rodauth. Vendors: Jeremy Evans.

Executive brief

Rodauth is a Ruby authentication framework used to secure user login for web applications. A flaw in the WebAuthn login feature allows attackers who are already logged in as one user to impersonate any other account without validating proper credential ownership, enabling account takeover and unauthorized access to other users' data.

Technical details

The vulnerability is an authentication bypass in the webauthn_login route caused by improper account resolution logic. When a user is already logged in, the authentication handler falls back to using session-based account identifiers instead of validating that the WebAuthn credential is properly bound to the target account. An attacker with an active session can exploit this to authenticate as any arbitrary account, whether or not that account has WebAuthn enabled. The flaw affects Rodauth versions prior to 2.46.0 and was fixed by enforcing credential-to-account binding validation. Exploitation requires an active authenticated session.

Affected products

  • Jeremy Evans Rodauth before 2.46.0

Timeline

  • 2026-08-29: disclosed
  • 2026-08-18: patched: Security fix committed to repository

References

Related threats