1 story taggedcve-2026-18963.
A 9.1-severity flaw in the popular open-source login server hands attackers full account takeover with no credentials required.