Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation.
Metrics
Affected Vendors & Products
References
History
Thu, 14 May 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Impersonation Vulnerability in Yubico WebAuthn Server Core 2.8.0–2.8.1 |
Thu, 14 May 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 14 May 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation. | |
| Weaknesses | CWE-253 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-14T02:06:22.112Z
Reserved: 2026-05-13T00:00:00.000Z
Link: CVE-2026-46419
No data.
Status : Received
Published: 2026-05-14T02:17:21.917
Modified: 2026-05-14T04:17:02.510
Link: CVE-2026-46419
No data.
OpenCVE Enrichment
Updated: 2026-05-14T03:30:10Z