CVE-2026-34348 is a protection-mechanism failure in the Windows Event Logging Service. Affected systems recorded complete WebAuthn/passkey assertion material, including authenticator data and cryptographic signature data, in Windows Event Logs. This exposure permitted authorized users able to access the relevant logs to obtain authentication material. Microsoft addressed the issue in its July 14, 2026 security updates by truncating logged signature fields to six bytes while retaining diagnostic utility.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real offensive/security-research toolkit centered on the 'Pass-the-Passkey' attack family rather than a minimal single-file PoC. The top-level wrapper README labels it as CVE-2026-34348 and embeds the upstream SpecterOps project. The substantive code lives under pass-the-passkey-SpecterOps and is primarily a Windows-focused C#/.NET solution with supporting PowerShell scripts, TypeScript/JavaScript bridge code, JSON configuration, and documentation. Repository structure: (1) Documentation explains two major components: SharpPasskeys and WebAuthnHook. (2) Src/Scripts contains PowerShell helpers for harvesting WebAuthn assertion responses from the Windows Event Log, monitoring/blocking/suspending browser processes during ceremonies, and chaining a captured PublicKeyCredential into a Microsoft Entra ID OAuth login/token flow. (3) Src/SpecterOps.Passkeys.Injector is a WPF/WebView2 GUI application that acts as a browser and intercepts navigator.credentials.get()/create() via an injected JS bridge exposed to C# through COM/WebView2 host objects. (4) Sample files include exported passkeys from Bitwarden, KeePassXC, and CXF-like credential exports, demonstrating the software-signing/replay use case. Main exploit capabilities: The Passkey Injector can intercept WebAuthn assertion and attestation requests inside its embedded browser, display parsed request details, accept pasted/crafted JSON responses, and return those to the page instead of native authenticator output. It also supports software signing using exported passkey material from files such as .passkey, Bitwarden JSON, and .cxf exports. The C2 commands dialog generates operator-ready commands for SharpPasskeys/Mythic/PowerShell workflows from captured assertion options. SharpPasskeys/WebAuthnHook capabilities, as documented in the repo, are more invasive: a native DLL is injected into browser processes and hooks WebAuthNAuthenticatorGetAssertion using Detours. The hook can observe rpId and clientData before prompting, replace the challenge, capture successful assertions as PublicKeyCredential JSON, and optionally deny the browser the result by returning a timeout. IPC is over the named pipe \\.\pipe\WebAuthnHook. The documented browser targeting includes msedge, chrome, firefox, brave, opera, and vivaldi. The PowerShell scripts extend the attack chain. Get-PasskeyAssertionEvent.ps1 queries Microsoft-Windows-WebAuthN/Operational for recent assertion-response events and reconstructs the PublicKeyCredential/origin. Invoke-PasskeyCircuitBreaker.ps1 watches WebAuthn events in real time and can suspend the browser process or create/remove outbound Windows Firewall rules for the browser executable. Invoke-EntraPasskeyInjection.ps1 is a PoC that takes a provided PublicKeyCredential JSON, drives a Microsoft login.microsoftonline.com authorization flow, and exchanges the resulting authorization code for tokens. Overall, this is an operational offensive research toolkit for local/browser/WebAuthn manipulation on Windows, enabling passkey capture, replay, challenge injection, and token acquisition workflows against Microsoft Entra ID and other WebAuthn-enabled relying parties. It is not merely a detector or README-only repo.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows/Entra login-related vulnerability referenced via a demo of exploit activity and identified as CVE-2026-34348; the content indicates it was fixed in July’s Windows Updates.
A Windows 11 information disclosure vulnerability in which complete WebAuthn assertion responses were logged to Windows Event Logs, enabling local attackers to harvest assertion material and potentially replay it against services with weak anti-replay validation.
An information disclosure vulnerability in the Windows Event Logging Service that exposed past YubiKey signatures in cleartext to authenticated unprivileged users, enabling a replay-style passkey attack chain against Microsoft Entra ID without extracting the authenticator private key.
A protection mechanism failure in the Windows Event Logging Service tied to Microsoft's passkey implementation, where Windows 11 logged a complete copy of passkey-related digital key material/assertions, enabling replay-style abuse as part of a 'Pass-the-Passkey' attack chain.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.