
CVE-2026-44166 Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker knows the email address of the victim they can… https://www.cve.org/CVERecord?id=CVE-2026-44166
Post summary
CVE-2026-44166 is a Pocketbase vulnerability affecting versions prior to 0.22.42/0.37.4 that allows an attacker to act upon a known victim email; no PoC, exploit code, or active exploitation is referenced, but patch information is implied.
