A low-privileged user can bypass account credentials...
High severity
Unreviewed
Published
Jan 23, 2026
to the GitHub Advisory Database
•
Updated Jan 23, 2026
Description
Published by the National Vulnerability Database
Jan 22, 2026
Published to the GitHub Advisory Database
Jan 23, 2026
Last updated
Jan 23, 2026
A low-privileged user can bypass account credentials without confirming the user's current authentication state, which may lead to unauthorized privilege escalation.
References