User Authentication Flaw in Pocketbase by Pocketbase Team
CVE-2026-44166

6.1MEDIUM

Key Information:

Vendor

Pocketbase

Vendor
CVE Published:
12 May 2026

What is CVE-2026-44166?

In Pocketbase, prior to versions 0.22.42 and 0.37.4, a specific vulnerability allows an attacker who knows a victim's email address to create an unverified user linked to that email. The attacker can leverage OAuth2 authentication using one provider to create this account. If the victim later attempts to sign up with a different OAuth2 provider, the malicious account created earlier will automatically be linked to the victim's legitimate account, marking it as verified and resetting its password. This highlights a significant weakness in user authentication processes, making it critical for users to update to the patched versions to mitigate this risk.

Affected Version(s)

pocketbase < 0.22.42 < 0.22.42

pocketbase >= 0.30.0, < 0.37.4 < 0.30.0, 0.37.4

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.