Improper Handling of Alternate Encoding in Wildfly Elytron - CVE-2026-19611
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to affected accounts.
The vulnerability exists due to improper handling of alternate encoding in password hashing and verification when normalizing passwords with Unicode NFKC. A remote attacker can use an ASCII-only dictionary to guess passwords intended to contain fullwidth non-ASCII characters to gain unauthorized access to affected accounts.
The issue affects passwords containing characters subject to NFKC compatibility folding.