Rodauth 2.46.0 之前的版本存在一个认证绕过漏洞,位于 路由中,该漏洞允许已登录用户以任意其他账户的身份进行认证。攻击者可利用不正确的账户解析逻辑——该逻辑在凭证绑定验证失败时会回退使用当前会话中的账户标识符——从而完成对任意用户的认证。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jeremyevans | rodauth | < 2.46.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jeremyevans | rodauth | 0 ~ 2.46.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82469 | 5.4 MEDIUM | Rodauth before 2.47.0 Authentication Bypass via jwt_refresh |
| CVE-2026-82470 | 5.4 MEDIUM | Rodauth before 2.47.0 TOTP Code Reuse via Drift Window |
| CVE-2026-82467 | 4.7 MEDIUM | Rodauth before 2.47.0 Open Redirect via Return-to Path |
| CVE-2026-82468 | 4.7 MEDIUM | Rodauth before 2.47.0 CSRF Protection Bypass via Content-Type |
No comments yet