CyberRota
← Ana sayfaya dön

CVE-2026-37982

MEDIUM · CVSS 6.8 EPSS %0.44

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-05-19T12:16:18.610 · Çekilme zamanı: 2026-06-17T12:01:17.560668+00:00

CyberRota Yorumu

Uzaktan istismar edilebilir olabilir.

CVE
CVE-2026-37982
Severity
MEDIUM
CVSS
6.8
EPSS
%0.44

Orijinal NVD Açıklaması

A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads to unauthorized enrollment of a hardware-backed credential, enabling persistent account takeover.