CVE@CVEnewDisclosure
The brief announcement highlights CVE‑2026‑32246, noting that Tinyauth's OIDC authorization endpoint before v5.0.3 incorrectly allows requests with a TOTP‑pending session, and points to a fix in v5.0.3.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces CVE‑2026‑32246, a 2FA bypass in Tinyauth’s OIDC endpoint before version 5.0.3, with no PoC, exploit, patch, or active exploitation details provided.
CVEFind.com@CveFindComPatch
The post announces that Tinyauth 5.0.3 resolves CVE-2026-32246, a 2FA bypass allowing attackers to obtain OIDC tokens without TOTP, but it does not provide a PoC, exploit, or active exploitation evidence.
The Hacker Wire@TheHackerWireDisclosure
The tweet announces a high‑severity flaw in Tinyauth’s OIDC authorization endpoint before version 5.0.3 that allows users with a pending TOTP session to proceed, but it does not provide exploitation details or remediation information.