MEDIUMVulnerability

CVE-2026-72780

Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can replay captured login request bodies containing requestOptions and response to create additional authenticated sessions for victim accounts.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-72780
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-11T13:19:08.510
last_modified
2026-08-28T18:45:00.010

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Authentication Bypass by Capture-replay

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72780 — Ninja Signal Threat Intelligence | Ninja Signal