megachangelog
Security3.4.14

Prevent external-IDP account pre-hijack and require authentication for WebAuthn/TOTP enrollment

Fixed a security vulnerability in Login V1 where external identity provider accounts could be pre-hijacked, and now requires authentication before enrolling WebAuthn, U2F, TOTP, or OTP methods.

3.4.14 (2026-07-29)

Bug Fixes

  • login: prevent external-IDP account pre-hijack in Login V1 (da67750)
  • login: require authentication before WebAuthn/U2F and TOTP/OTP enrollment (dd975b8)
securityauthenticationloginwebauthn

Source: original entry ↗