eduMFA: Unauthenticated Failcounter Increment on Resolver Tokens via /validate/check
Description
Published to the GitHub Advisory Database
May 18, 2026
Reviewed
May 18, 2026
Last updated
May 18, 2026
Impact
If the resolver parameter is passed, but the user does not exist, all failcounters of tokens in that resolver will be increased.
Patches
This, along with other issues, was fixed in eduMFA v2.9.1.
Workarounds
Limiting access to
/validate/checkto client applications (i.e. Shibboleth/FreeRADIUS) using an authorization policy withapi_key_requiredor using e.g. the reverse proxy.References