CVE Explorer
CVE-2026-44166
Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker knows the email address of the victim they can create and link an unverified PocketBase user in advance by authenticating with one of the OAuth2 app providers, e.g. "A". When the victim gets invited or decides to sign up to your app on their own with provider "B" (PocketBase OAuth2 auth requires to be with a different provider because we don't allow multiple OAuth2 accounts fro
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"pocketbase","vendor":"pocketbase","versions":[{"status":"affected","version":"< 0.22.42"},{"status":"affected","version":">= 0.30.0, < 0.37.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:150ebcd62e8adae9cd104133d3dda7baa79906365a383e4cdf43ecafe36e0c70 · sha256:93b2af2dde1467c1… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":6.1,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:150ebcd62e8adae9cd104133d3dda7baa79906365a383e4cdf43ecafe36e0c70 · sha256:93b2af2dde1467c1… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-287","description":"CWE-287: Improper Authentication","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:150ebcd62e8adae9cd104133d3dda7baa79906365a383e4cdf43ecafe36e0c70 · sha256:93b2af2dde1467c1… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/pocketbase/pocketbase/security/advisories/GHSA-pq7p-mc74-g65w","tags":["x_refsource_CONFIRM"],"url":"https://github.com/pocketbase/pocketbase/security/advisories/GHSA-pq7p-mc74-g65w"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:150ebcd62e8adae9cd104133d3dda7baa79906365a383e4cdf43ecafe36e0c70 · sha256:93b2af2dde1467c1… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.