CVE-2026-40947: Low severity Yubico libfido2 vulnerability
Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40947?
CVE-2026-40947 is categorized as a medium-severity vulnerability due to its unintended DLL search path flaw.
How do I fix CVE-2026-40947?
To remediate CVE-2026-40947, upgrade Yubico libfido2 to version 1.17.0 or newer, python-fido2 to version 2.2.0 or newer, and yubikey-manager to version 5.9.1 or newer.
What software is affected by CVE-2026-40947?
CVE-2026-40947 affects Yubico libfido2 before version 1.17.0, python-fido2 before version 2.2.0, and yubikey-manager before version 5.9.1.
What are the potential risks associated with CVE-2026-40947?
The unintended DLL search path in CVE-2026-40947 can potentially allow for unauthorized code execution if exploited.
When was CVE-2026-40947 disclosed?
CVE-2026-40947 was disclosed following the release of security advisories highlighting the vulnerability in the affected software.