PT-2026-27198 · Api · Api

Asdf2Adsfad

·

Published

2026-03-23

·

Updated

2026-03-27

·

CVE-2026-32879

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions New API versions 0.10.0 and later
Description A flaw exists in the universal secure verification flow, allowing an authenticated user with a registered passkey to bypass the WebAuthn assertion requirement. This issue affects actions protected by SecureVerificationRequired(). Specifically, the POST /api/verify endpoint, when receiving a request with {"method":"passkey"}, only verifies the existence of a registered passkey, failing to validate a completed WebAuthn assertion. This can lead to unauthorized access to sensitive information, such as channel secrets via the POST /api/channel/:id/key endpoint. Successful exploitation requires an existing authenticated session and a registered passkey.
Recommendations For versions 0.10.0 and later, do not rely on passkey as the step-up method for privileged secure-verification actions. Require TOTP/2FA for privileged secure-verification actions where possible. Temporarily restrict access to affected secure-verification-protected endpoints.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32879
GHSA-5353-F8FQ-65VC
GO-2026-4813
SUSE-SU-2026:1135-1

Affected Products

Api