CVE-2026-72780: Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey
Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can replay captured login request bodies containing requestOptions and response to create additional authenticated sessions for victim accounts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Craft CMSto a version that resolves this vulnerability.Fixed in 5.10.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72780?
The severity of CVE-2026-72780 is medium with a score of 6.5.
How do I fix CVE-2026-72780?
To fix CVE-2026-72780, you should update Craft CMS to version 5.10.5 or later.
What are the risks associated with CVE-2026-72780?
The risks associated with CVE-2026-72780 include the potential for attackers to create additional authenticated sessions for victim accounts via replay attacks.
What systems are affected by CVE-2026-72780?
CVE-2026-72780 affects Craft CMS versions before 5.10.5.
What is the exploit mechanism for CVE-2026-72780?
The exploit mechanism for CVE-2026-72780 involves replaying captured login request bodies at the passkey login endpoint.