Medium severity6.0NVD Advisory· Published Feb 24, 2025· Updated Apr 15, 2026
CVE-2025-23017
CVE-2025-23017
Description
WorkOS Hosted AuthKit before 2025-01-07 allows a password authentication MFA bypass (by enrolling a new authentication factor) when the attacker knows the user's password. No exploitation occurred.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.