Skip to main content
Vulnerability Database/CVE-2026-92087

CVE-2026-92087: Fastify Auth Plugin Bypass Vulnerability

CVE-2026-92087 is an authentication bypass flaw in @fastify/auth that allows attackers to circumvent security checks when using nested authentication strategies. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-92087 Overview

CVE-2026-92087 is an authorization bypass vulnerability in @fastify/auth, a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. Versions 5.0.0 through 5.1.0 evaluate nested AND groups in an order-dependent way when combined with the relation: "or" and run: "all" options. An earlier failing check is silently dropped, and the group's outcome collapses to the result of its last check. An attacker holding one valid credential can satisfy only the final member of an AND group and gain access intended for stricter role combinations. The issue is classified as Improper Authorization [CWE-285] and is fixed in version 5.1.1.

Critical Impact

A caller with a valid API key but no administrator role can be authorized on routes that require both, enabling privileged access to protected endpoints.

Affected Products

  • @fastify/auth 5.0.0
  • @fastify/auth 5.1.0 and all intermediate 5.x releases prior to the fix
  • Fastify applications composing strategies with relation: "or" plus run: "all" and nested AND groups, or the mirror and / nested or configuration

Discovery Timeline

  • 2026-09-16 - CVE-2026-92087 published to NVD
  • 2026-09-16 - Last updated in NVD database

Technical Details for CVE-2026-92087

Vulnerability Analysis

The @fastify/auth plugin allows developers to combine multiple authentication functions into a single preHandler using logical relations. Nested arrays represent AND groups, while the top-level relation option controls how those groups are combined. The run: "all" option instructs the plugin to execute every function rather than short-circuit on the first success.

Under this configuration, the evaluator overwrites the AND group's aggregate result with the outcome of each subsequent check instead of preserving prior failures. When the last check in an AND group succeeds, that success masks any earlier failure, producing a decision inconsistent with the declared policy. The result is a request being authorized when it should be rejected.

A symmetrical defect affects the mirror configuration, where the top-level relation is "and" and a nested group uses "or". In both cases, the ordering of predicates inside the group determines whether the guard enforces the intended composite policy.

Root Cause

The root cause is an accumulator error in the composed-strategy evaluator: the result variable for a nested group is reassigned on each iteration rather than combined with the group's logical operator. Earlier boolean failures are discarded silently, so the group evaluates to whatever its final predicate returned.

Attack Vector

Exploitation requires network access to an affected route and possession of at least one valid credential accepted by any strategy in the composition. An attacker submits a request that passes the last predicate of an AND group, such as presenting a valid API key while lacking the administrator role expected earlier in the group. The plugin then authorizes the request, granting access to functionality reserved for principals satisfying every check.

No exploit code is required beyond crafting a normal authenticated HTTP request with the partial credentials the attacker already controls. See the GitHub Security Advisory GHSA-7h52-2rwr-m76r for the maintainer's technical description.

Detection Methods for CVE-2026-92087

Indicators of Compromise

  • Successful requests to administrative or privileged Fastify routes from accounts that hold only a subset of the expected credentials, such as API-key-only sessions accessing admin endpoints.
  • Audit log entries showing role checks that failed followed by a successful authorization decision on the same request.
  • Deployment of @fastify/auth versions between 5.0.0 and 5.1.0 alongside route definitions using nested strategy arrays with run: "all".

Detection Strategies

  • Perform a dependency inventory across Node.js services and flag any application resolving @fastify/auth at a version in the vulnerable range.
  • Statically scan Fastify route definitions for fastify.auth([...], { relation: 'or', run: 'all' }) and the mirror and + nested or pattern.
  • Add authorization-decision logging inside each strategy function so downstream analysis can correlate individual predicate results with the final guard outcome.

Monitoring Recommendations

  • Ship Fastify access and application logs to a central analytics platform and alert on privileged route access by principals lacking the expected role claim.
  • Track anomalous authorization patterns, such as sudden increases in successful admin endpoint calls by API-key clients, and review them against expected role assignments.
  • Monitor for new deployments or container images that pin @fastify/auth to a vulnerable version and block promotion to production until upgraded.

How to Mitigate CVE-2026-92087

Immediate Actions Required

  • Upgrade @fastify/auth to version 5.1.1 or later across all services and rebuild any container images that bundle the dependency.
  • Audit every call site of fastify.auth(...) for compositions that mix relation: "or" with run: "all" and nested AND groups, or the mirror and plus nested or pattern.
  • Review recent access logs on routes protected by composed strategies for evidence of partial-credential access to privileged functionality.

Patch Information

The vulnerability is fixed in @fastify/auth 5.1.1. Update the dependency in package.json, refresh the lockfile with npm install or the equivalent for your package manager, and redeploy. Reference the OpenJS Foundation Security Advisories and GitHub Security Advisory GHSA-7h52-2rwr-m76r for advisory details.

Workarounds

  • Omit the run: "all" option on any composition where executing every strategy is not required.
  • Reorder each AND group so the strictest check is evaluated last, ensuring its result determines the group outcome.
  • Replace nested AND groups with an explicit top-level "and" composition, eliminating the vulnerable nested-array pattern entirely.
bash
# Configuration example
npm install @fastify/auth@^5.1.1
npm ls @fastify/auth

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.