Количество 4
Количество 4
CVE-2026-37982
A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads to unauthorized enrollment of a hardware-backed credential, enabling persistent account takeover.
CVE-2026-37982
A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads to unauthorized enrollment of a hardware-backed credential, enabling persistent account takeover.
CVE-2026-37982
A flaw was found in Keycloak. This authentication vulnerability allows ...
GHSA-w4p5-rfh6-cwrv
Keycloak: Unauthorized account takeover via WebAuthn token replay
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-37982 A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads to unauthorized enrollment of a hardware-backed credential, enabling persistent account takeover. | CVSS3: 6.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-37982 A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads to unauthorized enrollment of a hardware-backed credential, enabling persistent account takeover. | CVSS3: 6.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-37982 A flaw was found in Keycloak. This authentication vulnerability allows ... | CVSS3: 6.8 | 0% Низкий | 3 месяца назад | |
GHSA-w4p5-rfh6-cwrv Keycloak: Unauthorized account takeover via WebAuthn token replay | CVSS3: 6.8 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу