Identity CVE · FIDO2 / WebAuthn
CVE-2025-26788StrongKey FIDO Server credential-type confusion, passkey bypass
high
Product: StrongKey FIDO ServerVendor: StrongKeyDisclosed: 2025-02-18Status: PatchedProtocol deep diveNVD ↗
What broke
StrongKey FIDO Server (4.10.0 through 4.15.0) mixed up discoverable and non-discoverable credentials. The server would accept an assertion for the wrong credential type and authenticate the attacker as the victim. High. StrongKey patched.
Why it matters
On-prem FIDO2 servers are how regulated environments get passkeys without sending every ceremony to a cloud IdP. A credential-type confusion is a passkey auth bypass with no phishing required. It is the server-side cousin of CVE-2026-34348 (logging) and of Keycloak's fmt:none attestation-policy bypass.
What to do
- Upgrade StrongKey FIDO Server off the 4.10-4.15 line.
- Confirm your FIDO server still distinguishes resident / discoverable keys from server-side credentials after the upgrade.
- Review authentication logs for ceremonies that succeeded with an unexpected credential type.
Sources
Related identity CVEs
Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.