SB2026072923 - Authentication Bypass by Capture-replay in Craft CMS



SB2026072923 - Authentication Bypass by Capture-replay in Craft CMS

Published: July 29, 2026

Security Bulletin ID SB2026072923
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Authentication Bypass by Capture-replay (CVE-ID: N/A)

CWE-ID: CWE-294 - Authentication Bypass by Capture-replay

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to hijack another user's session.

The vulnerability exists due to authentication bypass by capture-replay in the passkey login flow when handling a replayed WebAuthn assertion in a crafted login request body. A remote attacker can repost a captured passkey login request body to hijack another user's session.

Exploitation requires exposure of one successful passkey login request body containing the WebAuthn requestOptions and response.


Remediation

Install update from vendor's website.