CVE-2026-32246: Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint
(updated )
The OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet completed) to obtain authorization codes. An attacker who knows a user’s password but not their TOTP secret can obtain valid OIDC tokens, completely bypassing the second factor.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-32246 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →