A AegiFlow
CRITICALCVSS 9.8

CVE-2026-19117

CVE-2026-19117 updated by NVD

Modified
2026-09-05
Sources
nvd

Summary

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.