MFA Bypass Vulnerability in WorkOS Hosted AuthKit
CVE-2025-23017

6MEDIUM

Key Information:

Vendor

Workos

Vendor
CVE Published:
24 February 2025

What is CVE-2025-23017?

A vulnerability has been identified in WorkOS Hosted AuthKit which allows attackers to bypass multi-factor authentication (MFA) by enrolling a new authentication factor if they are aware of the user's password. This flaw potentially exposes user accounts to unauthorized access. Users are encouraged to monitor their accounts and update to the latest version to mitigate any risks associated with this security issue.

Affected Version(s)

Hosted AuthKit 0 < 2025-01-07

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.