Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet completed) to obtain authorization codes. An attacker who knows a user's password but not their TOTP secret can obtain valid OIDC tokens, completely bypassing the second factor. This vulnerability is fixed in 5.0.3.
References
Configurations
No configuration.
History
12 Mar 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-12 19:16
Updated : 2026-03-12 21:07
NVD link : CVE-2026-32246
Mitre link : CVE-2026-32246
CVE.ORG link : CVE-2026-32246
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
