PocketBase, an open source web backend written in Go, is vulnerable prior to versions 0.22.42 and 0.37.4 to an account pre-hijacking flaw in its OAuth2 account-linking logic. In affected versions, if an attacker knows a victim's email address, the attacker can first create an unverified PocketBase user associated with that email by authenticating through one OAuth2 provider. Later, when the legitimate victim is invited or signs up using a different OAuth2 provider, PocketBase may automatically link the victim's new authentication flow to the attacker-created account, upgrade that account to verified status, and reset its old password. The issue arises from unsafe autolinking behavior during the transition from an attacker-created unverified account to a verified account tied to the victim identity, allowing previously established attacker-controlled OAuth2 linkage to persist.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Python PoC and verification lab for CVE-2026-44166, an OAuth2 account pre-hijacking flaw in PocketBase. It is not tied to a common exploit framework. The repo contains 7 files total, with 4 code files: fetch_binaries.py downloads PocketBase 0.37.3 and 0.37.4 release binaries from GitHub; mock_oauth2_server.py starts a local offline OAuth2/OIDC-like provider on 127.0.0.1:8089; poc.py launches vulnerable PocketBase 0.37.3 locally on 127.0.0.1:8090, creates a superuser and an OAuth2-enabled auth collection, then exploits /api/collections/members/auth-with-oauth2 by submitting attacker_code together with createData.email set to victim@company.com; verify_fix.py repeats the same workflow against an arbitrary version to compare vulnerable versus patched behavior. The exploit capability is account pre-claiming: the attacker uses their own OAuth2 identity but injects a victim email into createData, causing PocketBase to create a record with the victim email linked to the attacker’s provider identity. In the demonstrated single-provider scenario, the victim is later locked out with HTTP 400 while the attacker can still re-authenticate to the same record. The writeup also explains a multi-provider co-ownership variant. All network activity in the repository is local/offline except binary download from GitHub; there is no external victim target hardcoded beyond the local lab endpoints.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.