CVE-2026-32246Disclosure(tinyauth / tinyauth)

LOWCVSS 7.1 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch tinyauth tinyauth systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet completed) to obtain authorization codes. An attacker who knows a user's password but not their TOTP secret can obtain valid OIDC tokens, completely bypassing the second factor. This vulnerability is fixed in 5.0.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tinyauth

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
tinyauth

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-12: 4Patch / Workaround · 2026-03-12: 2Technical Details · 2026-03-12: 403-12
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32246 Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (password verified, T… https://www.cve.org/CVERecord?id=CVE-2026-32246

    Post summary

    The brief announcement highlights CVE‑2026‑32246, noting that Tinyauth's OIDC authorization endpoint before v5.0.3 incorrectly allows requests with a TOTP‑pending session, and points to a fix in v5.0.3.

    00000142
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32246 Two-Factor Authentication Bypass in Tinyauth OIDC Authorization Endpoint Before 5.0.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32246

    Post summary

    The post announces CVE‑2026‑32246, a 2FA bypass in Tinyauth’s OIDC endpoint before version 5.0.3, with no PoC, exploit, patch, or active exploitation details provided.

    0000033
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32246: HIGH] Cyber security alert: Tinyauth 5.0.3 fixes a critical vulnerability allowing attackers to bypass 2FA and obtain valid OIDC tokens without TOTP completion. #cybersecurity#cve,CVE-2026-32246,#cybersecurity https://cvefind.com/CVE-2026-32246

    Post summary

    The post announces that Tinyauth 5.0.3 resolves CVE-2026-32246, a 2FA bypass allowing attackers to obtain OIDC tokens without TOTP, but it does not provide a PoC, exploit, or active exploitation evidence.

    0000060
    602 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32246 - High Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet completed) to... https://www.thehackerwire.com/vulnerability/CVE-2026-32246/ https://t.co/yqHhmMKGtS

    Post summary

    The tweet announces a high‑severity flaw in Tinyauth’s OIDC authorization endpoint before version 5.0.3 that allows users with a pending TOTP session to proceed, but it does not provide exploitation details or remediation information.

    0000033
    134 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptinyauthtinyauth---

Explore more