Tag
critical
advisory
Critical Unauthenticated Remote Code Execution in OpenAM WebAuthn due to Deserialization Vulnerability (CVE-2026-62263)
2 TTPsA critical remote code execution (RCE) vulnerability, CVE-2026-62263, exists in OpenAM's WebAuthn authenticator deserialization, allowing an unauthenticated attacker to bypass an `ObjectInputFilter` and execute arbitrary code by crafting a malicious serialized stream before authentication.
openam-auth-webauthn
deserialization
rce
webauthn
java
openam
vulnerability
2t
high
advisory
eduMFA Passkey Replay Vulnerability
2 ruleseduMFA versions prior to 2.9.1 are vulnerable to replay attacks due to a missing expiration flag in userless Passkey/WebAuthn challenges, potentially leading to unauthorized access.
eduMFA
replay-attack
authentication
webauthn
2r
high
advisory
fido2-lib Denial-of-Service Vulnerability via CBOR Parsing
2 rules 1 TTPThe fido2-lib library is vulnerable to a denial-of-service (DoS) attack due to a heap buffer over-read in the cbor-extract dependency when parsing CBOR attestation data, allowing an attacker to crash the server by sending a crafted CBOR payload during WebAuthn registration.
fido2-lib
cbor-extract
denial-of-service
webauthn
2r
1t