CVE-2026-32246

HIGH

Tinyauth <5.0.3 - Auth Bypass

Title source: llm

Description

Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet completed) to obtain authorization codes. An attacker who knows a user's password but not their TOTP secret can obtain valid OIDC tokens, completely bypassing the second factor. This vulnerability is fixed in 5.0.3.

Scores

CVSS v3 8.5
EPSS 0.0004
EPSS Percentile 13.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N

Details

CWE
CWE-287
Status published
Products (2)
steveiliop56/tinyauth 0 - 1.0.1-20260311144920-9eb2d33064b7Go
tinyauth/tinyauth < 5.0.2
Published Mar 12, 2026
Tracked Since Mar 13, 2026