Authentication Bypass by Capture-replay in Craft CMS - #VU139965
Published: July 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to hijack another user's session.
The vulnerability exists due to authentication bypass by capture-replay in the passkey login flow when handling a replayed WebAuthn assertion in a crafted login request body. A remote attacker can repost a captured passkey login request body to hijack another user's session.
Exploitation requires exposure of one successful passkey login request body containing the WebAuthn requestOptions and response.