CVE-2024-12838
The passwordless login mechanism in CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability, allowing remote attackers with regular privileges to send a crafted request to switch to the identity of any user, including administrators.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.74%
- CWE
- CWE-302
- Published
- 2024-12-31
- Last modified
- 2026-03-13
Affected products
- Changing Information Technology CGFIDO
Weakness type
Related vulnerabilities
- CVE-2026-77508 — Weblate: Unverified REST API email changes
- CVE-2026-13267 — Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
- CVE-2026-5423 — Subscription Authentication Bypass via Unverified connectionParams.jwt
- CVE-2026-50528 — .NET Security Feature Bypass Vulnerability
- CVE-2026-47303 — ASP.NET Core Elevation of Privilege Vulnerability
- CVE-2026-48117 — DroneAware's Improper Account Activation in Registration and SSO Flows Leads to Account Takeover
- CVE-2026-48781 — Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
- CVE-2026-34460 — NamelessMC: OAuth callback `state` is not validated, allowing login CSRF / session swapping