Improper Authentication in Mastodon - #VU147214
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to log in to affected accounts without a valid password.
The vulnerability exists due to improper authentication in Mastodon\'s authentication flow when processing sign-in attempts for accounts without database-stored passwords. A remote attacker can provide any password and proceed to second-factor authentication to log in to affected accounts without a valid password.
Exploitation requires a valid security key, backup code, or TOTP token for an account with two-factor authentication enabled that uses LDAP, PAM, or server-configured SSO.