WebAuthn Assertion Replay Vulnerability in Craft CMS by Pixel & Tonic
CVE-2026-72780
7.1HIGH
What is CVE-2026-72780?
Craft CMS prior to version 5.10.5 is susceptible to a security flaw that allows attackers to replay captured login request bodies. Specifically, during the passkey login process, the system fails to properly persist updated credential counters after WebAuthn assertion validation. This vulnerability potentially enables unauthorized individuals to create additional authenticated sessions for user accounts, compromising the integrity of the authentication mechanism.
Affected Version(s)
cms 5.0.0-RC1 < 5.10.5
cms 5.10.5
