Vulnerability library
Security checkMarch 06, 2026

OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing cre

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

The WebAuthn authentication implementation does not store the challenge on the server side. Instead, the challenge is returned to the client and accepted back from the client request body during verification. This violates the WebAuthn specification (W3C Web Authentication Level 2, §13.4.

Recommendation

No fix is available yet. Followings are affected versions:

  • <= 10.0.11

References

Could your website be exposed too?

SmartScanner can check your website for OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing cre and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated March 06, 2026