User Authentication Flaw in Pocketbase by Pocketbase Team
CVE-2026-44166
6.1MEDIUM
What is CVE-2026-44166?
In Pocketbase, prior to versions 0.22.42 and 0.37.4, a specific vulnerability allows an attacker who knows a victim's email address to create an unverified user linked to that email. The attacker can leverage OAuth2 authentication using one provider to create this account. If the victim later attempts to sign up with a different OAuth2 provider, the malicious account created earlier will automatically be linked to the victim's legitimate account, marking it as verified and resetting its password. This highlights a significant weakness in user authentication processes, making it critical for users to update to the patched versions to mitigate this risk.
Affected Version(s)
pocketbase < 0.22.42 < 0.22.42
pocketbase >= 0.30.0, < 0.37.4 < 0.30.0, 0.37.4
