Authentication Bypass by Capture-replay in Craft CMS - #VU139965

 

Authentication Bypass by Capture-replay in Craft CMS - #VU139965

Published: July 29, 2026


Vulnerability identifier: #VU139965
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-294
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to hijack another user's session.

The vulnerability exists due to authentication bypass by capture-replay in the passkey login flow when handling a replayed WebAuthn assertion in a crafted login request body. A remote attacker can repost a captured passkey login request body to hijack another user's session.

Exploitation requires exposure of one successful passkey login request body containing the WebAuthn requestOptions and response.


Affected software

Craft CMS

Remediation

Install security update from vendor's website.

Craft CMS - update to 5.10.5

External References

Related Security Bulletins