Web Hack List

Collected research

CVE-2025-26788: Passkey Authentication Bypass in StrongKey FIDO Server

StrongKey FIDO Server fails to distinguish the discoverable from the non-discoverable WebAuthn authentication flow. An attacker begins preauthentication with the victim's username, replaces the returned allowed credential identifier with their own, signs the challenge with their own passkey, and is logged in as the victim.

Record

Researcher
Natalia Trojanowska-Korepta
Published by
Securing
Date
Format
Advisory
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Natalia Trojanowska-Korepta, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .