Authentication Bypass Vulnerability in On-Premises FIDO2 Implementations by Delinea
CVE-2026-19117
9.8CRITICAL
What is CVE-2026-19117?
This vulnerability allows an attacker to register a FIDO2 credential controlled by them against a target account under specific conditions. Once registered, the attacker can authenticate as the legitimate user, potentially leading to unauthorized access to sensitive information. This issue affects only on-premises deployments, highlighting the need for vigilant oversight and prompt remediation.
Affected Version(s)
Secret Server (On-Prem) Windows 10.6.0 <= 11.7.61
Secret Server (On-Prem) Windows 11.8.0 <= 11.8.1
Secret Server (On-Prem) Windows 11.9.0 <= 11.9.47
