SB2026072923 - Authentication Bypass by Capture-replay in Craft CMS
Published: July 29, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Authentication Bypass by Capture-replay (CVE-ID: N/A)
CWE-ID: CWE-294 - Authentication Bypass by Capture-replay
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to hijack another user's session.
The vulnerability exists due to authentication bypass by capture-replay in the passkey login flow when handling a replayed WebAuthn assertion in a crafted login request body. A remote attacker can repost a captured passkey login request body to hijack another user's session.
Exploitation requires exposure of one successful passkey login request body containing the WebAuthn requestOptions and response.
Remediation
Install update from vendor's website.