CVE-2026-46419
Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.31%
- CWE
- CWE-253
- Published
- 2026-05-14
- Last modified
- 2026-05-14
Affected products
- Yubico webauthn-server-core
Weakness type
Related vulnerabilities
- CVE-2026-15686 — Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability
- CVE-2026-59847 — Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification
- CVE-2026-5818 — MCU Firmware Update Authentication Bypass on Caliptra Core
- CVE-2026-43863 — mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
- CVE-2026-35340 — uutils coreutils chown and chgrp False Success Exit Code in Recursive Mode
- CVE-2026-35339 — uutils coreutils chmod False Success Exit Code in Recursive Mode
- CVE-2026-35091 — Corosync: corosync: denial of service and information disclosure via crafted udp packet
- CVE-2026-0648 — The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in...