7.6
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
Description
CVE-2026-44166 — PocketBase OAuth2 Account Pre-Hijacking Self-contained lab + writeup for CVE-2026-44166: an attacker with any account on a configured OAuth2 provider can pre-claim a victim's email on an OAuth2-enabled PocketBase collection, locking...
Basic Information
ID
98D7FC0C-3955-56D1-8337-74FE94A341E4
Published
Jun 11, 2026 at 02:06
Modified
Jun 11, 2026 at 02:10