Dark C0d3rs

Full Version: HackerOne Disclosed Reports - 2025-10-21
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Logo
Medium
resolved

2FA bypass possible on https://authsvc.singlestore.com


Bug reported by Axolot was disclosed at October 22, 2025, 6:44 am   |   Authentication Bypass

A vulnerability was discovered that allowed the 2FA authentication mechanism to be bypassed completely. An attacker could access the victim's account by only knowing the email address and password, without requiring the 2FA code.