CVE-2026-19117
Received Received - Intake

FIDO2 Credential Registration Bypass in On-Premises Deployment

Vulnerability report for CVE-2026-19117, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Delinea

Description

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
delinea cloud_suite to 25.2_hf1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an attacker to register a malicious FIDO2 credential for a target account and then impersonate that user. It only affects on-premises deployments.

Impact Analysis

An attacker could gain unauthorized access to user accounts, leading to data breaches, privilege escalation, or further system compromise. The high CVSS score (9.8) indicates severe potential impact.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR (data protection) and HIPAA (health information privacy) requirements. Non-compliance may result in legal penalties and reputational damage.

Mitigation Strategies

Since this vulnerability affects on-premises deployments, ensure all Delinea Cloud Suite instances are updated to the latest version. Monitor authentication logs for suspicious FIDO2 credential registrations. Restrict network access to administrative interfaces and review user accounts for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19117. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart