CVE-2026-33544 identifies a high-severity race condition in Tinyauth, an authentication and authorization server, affecting versions prior to 5.0.5. This flaw allows one user to receive a session with another user's identity when two users concurrently initiate OAuth login for the same provider. Rated 7.7 HIGH (CVSS:3.1), the vulnerability requires network access, low privileges, and user interaction, but results in high impact to confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, with an EPSS score indicating a very low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.5CPE matchmatch criteria | cpe:2.3:a:tinyauth:tinyauth:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.