MFA Bypass Vulnerability in WorkOS Hosted AuthKit
CVE-2025-23017
6MEDIUM
What is CVE-2025-23017?
A vulnerability has been identified in WorkOS Hosted AuthKit which allows attackers to bypass multi-factor authentication (MFA) by enrolling a new authentication factor if they are aware of the user's password. This flaw potentially exposes user accounts to unauthorized access. Users are encouraged to monitor their accounts and update to the latest version to mitigate any risks associated with this security issue.
Affected Version(s)
Hosted AuthKit 0 < 2025-01-07