SQL Injection Vulnerability in YubiServer by Yubico
CVE-2015-0842

Currently unrated

Key Information:

Vendor

Yubiserver

Vendor
CVE Published:
26 June 2025

What is CVE-2015-0842?

YubiServer versions prior to 0.6 contain a critical SQL injection vulnerability that can be exploited to bypass authentication mechanisms. This weakness could allow unauthorized users to gain access to sensitive data and functionalities, posing a significant risk to system integrity and security. It is essential for users to update to the latest version to mitigate this issue.

Affected Version(s)

yubiserver 0 < 0.6

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2015-0842 : SQL Injection Vulnerability in YubiServer by Yubico