AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72780

MEDIUM · CVSS 6.5 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Craft CMS versions prior to 5.10.5 are vulnerable due to a failure to properly persist updated credential counters in the passkey login endpoint, allowing attackers to replay captured login requests. This could lead to unauthorized access, enabling attackers to create additional authenticated sessions for victim accounts. Organizations using affected versions should prioritize patching to mitigate the risk of account compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72780
Severity
MEDIUM
CVSS
6.5
EPSS
0.23%

Original NVD Description

Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can replay captured login request bodies containing requestOptions and response to create additional authenticated sessions for victim accounts.