PT-2026-96161 · Tinyauth · Tinyauth
CVE-2026-77560
·
Published
2026-09-21
·
Updated
2026-09-22
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Tinyauth versions prior to 5.1.2
Description
Tinyauth performs case-sensitive comparisons of forwarded hostnames, whereas reverse proxies typically route equivalent hostnames case-insensitively. This discrepancy allows an authenticated user with low privileges to bypass per-app access controls by using a hostname with different casing. Specifically, the
lookupStaticACLs() and GetAccessControls() functions in internal/service/access controls service.go, as well as the GetLabels() function in internal/service/docker service.go, may fail to identify the configured application and return an empty access-control object. Consequently, the proxyHandler() in internal/controller/proxy controller.go treats empty restrictions for users, groups, OAuth, LDAP, and IP as permissive, granting access to an application that should have excluded the user. Unauthenticated users are still required to log in, and global login-time allowlists remain effective.Recommendations
Update to version 5.1.2.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tinyauth