Improper Authentication Affecting ruby-rodauth package, versions <2.46.0-1


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.34% (27th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-RUBYRODAUTH-19430520
  • published30 Aug 2026
  • disclosed29 Aug 2026

Introduced: 29 Aug 2026

NewCVE-2026-82466  (opens in a new tab)
CWE-287  (opens in a new tab)

How to fix?

Upgrade Debian:unstable ruby-rodauth to version 2.46.0-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream ruby-rodauth package and not the ruby-rodauth package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account identifiers instead of validating the credential binding to complete authentication as arbitrary users.

CVSS Base Scores

version 3.1