HIGHVulnerability

CVE-2026-82466

Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account identifiers instead of validating the credential binding to complete authentication as arbitrary users.

Properties

severity
HIGH
score
8.7
epss_score
0.00338
cve_id
CVE-2026-82466
signal_observed_at
2026-09-15T21:12:48+00:00
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
published_at
2026-08-29T17:17:58.910
last_modified
2026-09-11T18:26:53.610
epss_percentile
0.2702

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Authentication

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82466 — Ninja Signal Threat Intelligence | Ninja Signal