Description
@fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. In versions 5.0.0 through 5.1.0, when strategies are composed with the relation "or" option together with the run "all" option and one entry is a nested array acting as an AND group, the group is evaluated in an order-dependent way: an earlier failing check is silently dropped and the group's result becomes the outcome of its last check. As a result, a request that satisfies only the last member of an AND group, for example an attacker who holds a valid API key but is not an administrator, is authorized instead of rejected, and a related order-dependent bypass affects the mirror configuration where the top-level relation is "and" and a nested group uses "or". The issue is fixed in @fastify/auth 5.1.1, and users should upgrade to 5.1.1 or later. As a workaround, omit the run "all" option where it is not required, order each AND group so its stricter check is evaluated last, or replace nested AND groups with an explicit top-level "and" composition.
Published: 2026-09-16
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Immediate Upgrade
AI Analysis

Impact

@fastify/auth is a Fastify plugin that combines multiple authentication and authorization strategies for route protection. In versions 5.0.0 through 5.1.0, using the “or” relation together with the run “all” option and a nested array that represents an AND group results in order‑dependent evaluation. The engine discards an earlier failing check and uses the outcome of the last check in the group. Consequently, a request that satisfies only the last member of an AND group, such as a user with a valid API key but not an administrator, is incorrectly authorized. This flaw allows attackers to obtain privileges they should not have, effectively bypassing configured authorization controls.

Affected Systems

The vulnerability affects the @fastify/auth plugin for Fastify, specifically versions 5.0.0 through 5.1.0. Users running those releases on any Fastify application that employs composite auth strategies are potentially exposed. Versions 5.1.1 and later contain the fix.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.1, indicating high severity. The EPSS score is below 1 %, implying a very low probability of widespread exploitation at this time, and the issue is not listed in the CISA KEV catalog. Exploitation requires sending crafted HTTP requests to routes protected by the affected auth composition; the attack is remote and does not require privileged local access. Organizations should treat the flaw as significant if they rely on fine‑grained authorization, especially when using nested AND groups with the “or” relation.

Generated by OpenCVE AI on September 18, 2026 at 04:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade @fastify/auth to version 5.1.1 or later, which corrects the order‑dependent evaluation logic.
  • If upgrading is not immediately possible, remove the run "all" option from the auth configuration where it is not required.
  • Rearrange the order of checks in each AND group so that the stricter condition is evaluated last, or replace nested AND groups with an explicit top‑level "and" composition.
  • Verify that no legacy or custom authentication strategies remain that could re‑introduce the flaw.

Generated by OpenCVE AI on September 18, 2026 at 04:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Fastify
Fastify auth
Vendors & Products Fastify
Fastify auth

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description @fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. In versions 5.0.0 through 5.1.0, when strategies are composed with the relation "or" option together with the run "all" option and one entry is a nested array acting as an AND group, the group is evaluated in an order-dependent way: an earlier failing check is silently dropped and the group's result becomes the outcome of its last check. As a result, a request that satisfies only the last member of an AND group, for example an attacker who holds a valid API key but is not an administrator, is authorized instead of rejected, and a related order-dependent bypass affects the mirror configuration where the top-level relation is "and" and a nested group uses "or". The issue is fixed in @fastify/auth 5.1.1, and users should upgrade to 5.1.1 or later. As a workaround, omit the run "all" option where it is not required, order each AND group so its stricter check is evaluated last, or replace nested AND groups with an explicit top-level "and" composition.
Title @fastify/auth vulnerable to Authorization Bypass via order-dependent evaluation of composed auth
Weaknesses CWE-285
CWE-697
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: openjs

Published:

Updated: 2026-09-17T19:10:19.438Z

Reserved: 2026-09-15T13:56:18.212Z

Link: CVE-2026-92087

cve-icon Vulnrichment

Updated: 2026-09-17T19:10:13.895Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:18:59.653

Modified: 2026-09-17T20:18:55.393

Link: CVE-2026-92087

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:00:04Z

Weaknesses