Intruder logoIntruder logo

Insights

CVE-2025-26788

Published Feb 14, 2025

Last updated 3 months ago

CVSS high 8.4
  1. Overview

  2. Scores

  3. Weaknesses

  4. Social media

  5. References

Overview

Description
StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.
Source
cve@mitre.org
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.4
Impact score
6
Exploitability score
1.8
Vector string
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Severity
HIGH

Weaknesses

cve@mitre.org
CWE-639

Social media

Hype score
Not currently trending
  1. ๐Ÿšจ CVE-2025-26788 ๐Ÿ”ด HIGH (8.4) ๐Ÿข StrongKey - FIDO Server ๐Ÿ—๏ธ 0 ๐Ÿ”— https://t.co/hyEBe9LY5x #CyberCron #VulnAlert https://t.co/jwzYzHByBT

    @cybercronai

    16 Feb 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. [CVE-2025-26788: HIGH] StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.#cybersecurity,#vulnerability https://t.co/GPuMGnP1Zs https://t.co/EIkhY6T8Jb

    @CveFindCom

    14 Feb 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.

  • https://nvd.nist.gov/vuln/detail/CVE-2025-26788
  • https://docs.strongkey.com/index.php/skfs-v3/skfs-release-notes
  • https://www.securing.pl/en/cve-2025-26788-passkey-authentication-bypass-in-strongkey-fido-server/
TRY INTRUDER
Intruder logo

ยฉ 2025 Intruder Systems Ltd.

AboutPrivacySitemapFeeds