Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 14 May 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Impersonation Vulnerability in Yubico WebAuthn Server Core 2.8.0–2.8.1 |
Thu, 14 May 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 14 May 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation. | |
| Weaknesses | CWE-253 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-14T02:06:22.112Z
Reserved: 2026-05-13T00:00:00.000Z
Link: CVE-2026-46419
No data.
Status : Received
Published: 2026-05-14T02:17:21.917
Modified: 2026-05-14T04:17:02.510
Link: CVE-2026-46419
No data.
OpenCVE Enrichment
Updated: 2026-05-14T03:30:10Z
Weaknesses