CVE-2026-72780 | Craft CMS up to 5.10.4 Passkey Login Endpoint authentication replay
A vulnerability was found in Craft CMS CMS up to 5.10.4. It has been classified as critical. This vulnerability affects unknown code of the component Passkey Login Endpoint. The manipulation leads to authentication bypass by capture-replay.
This vulnerability is uniquely identified as CVE-2026-72780. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More