PT-2026-27198 · Api · Api

Asdf2Adsfad

·

Publicado

2026-03-23

·

Atualizado

2026-03-27

·

CVE-2026-32879

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions New API versions 0.10.0 and later
Description A flaw exists in the universal secure verification flow, allowing an authenticated user with a registered passkey to bypass the WebAuthn assertion requirement. This issue affects actions protected by SecureVerificationRequired(). Specifically, the POST /api/verify endpoint, when receiving a request with {"method":"passkey"}, only verifies the existence of a registered passkey, failing to validate a completed WebAuthn assertion. This can lead to unauthorized access to sensitive information, such as channel secrets via the POST /api/channel/:id/key endpoint. Successful exploitation requires an existing authenticated session and a registered passkey.
Recommendations For versions 0.10.0 and later, do not rely on passkey as the step-up method for privileged secure-verification actions. Require TOTP/2FA for privileged secure-verification actions where possible. Temporarily restrict access to affected secure-verification-protected endpoints.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32879
GHSA-5353-F8FQ-65VC
GO-2026-4813
SUSE-SU-2026:1135-1

Produtos afetados

Api