WebAuthn Assertion Replay Vulnerability in Craft CMS by Pixel & Tonic
CVE-2026-72780

7.1HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72780?

Craft CMS prior to version 5.10.5 is susceptible to a security flaw that allows attackers to replay captured login request bodies. Specifically, during the passkey login process, the system fails to properly persist updated credential counters after WebAuthn assertion validation. This vulnerability potentially enables unauthorized individuals to create additional authenticated sessions for user accounts, compromising the integrity of the authentication mechanism.

Affected Version(s)

cms 5.0.0-RC1 < 5.10.5

cms 5.10.5

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.