StrongKey FIDO Server before version 4.15.1 incorrectly treats a non-discoverable credential (namedcredential) authentication flow as a discoverable transaction. This indicates a logic flaw in the server’s handling of FIDO/WebAuthn credential types or transaction state, where a request intended for a non-discoverable credential path is processed under discoverable-credential semantics. Based on the available information, the issue is a server-side authentication/authorization logic error rather than a memory-safety flaw.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small proof-of-concept lab for CVE-2025-26788 centered on StrongKey FIDO Server (SKFS) 4.15.0. It contains four files: a README with setup steps, a Dockerfile for a Rocky Linux 9.3 systemd-based container, a Bash installer script that provisions SKFS and its sample application, and a text file containing JavaScript payloads for browser-side WebAuthn/passkey interception and manipulation. Repository structure and purpose: - dockerfile: Builds a Rocky Linux 9.3 container with systemd support and minimal utilities, intended to host SKFS. - setup-skfs.sh: Installs dependencies (OpenLDAP, Java 21, curl, unzip, sudo), downloads StrongKey FIDO Server v4.15.0 and the basicdemo WAR from SourceForge, patches the installer to use RPID skfs.localdomain, deploys the sample app to Payara, and configures the tutorial API URI to https://skfs.localdomain:8181. - README.md: Documents how to build/run the container, copy and execute setup-skfs.sh, add a hosts-file entry for skfs.localdomain, and launch Chrome with flags that bypass certificate/origin restrictions for local testing. - passkey payload.txt: Contains the actual exploit logic in JavaScript snippets intended for injection into a browser context, likely via DevTools or another script injection method. Main exploit capability: The exploit is browser-based and targets WebAuthn/passkey authentication flows. It hooks navigator.credentials.get, inspects options.publicKey.allowCredentials, logs credential IDs in raw and Base64 form, and in the more aggressive variant replaces each credential ID with a hardcoded attacker credential ID. This indicates an attempt to subvert credential selection during authentication by forcing the browser/WebAuthn flow to use an attacker-chosen credential identifier. Operational characteristics: - The exploit is not a standalone remote exploit; it is a lab-oriented operational PoC requiring a controlled SKFS deployment and browser-side code execution. - It relies on a specific relying party ID/origin setup: skfs.localdomain over port 8181. - It uses insecure Chrome flags to make local HTTPS/WebAuthn testing easier despite certificate issues. - The payload is hardcoded rather than parameterized, which fits OPERATIONAL maturity rather than fully weaponized tooling. Overall, this repository is best understood as a reproducible test environment plus browser payloads for demonstrating or researching WebAuthn/passkey credential ID disclosure and tampering against a StrongKey FIDO Server deployment associated with CVE-2025-26788.
9 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.