← Back to overview

CVE-2026-19117 describes a vulnerability affecting on-premises deployments where, under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target user account. Once the rogue credential is registered, the attacker can authenticate as the targeted user without their knowledge or consent. The vulnerability is limited to on-premises deployments and does not affect cloud-hosted instances. The issue is tracked by Delinea, which has published a security advisory. Successful exploitation could lead to full account takeover, bypassing multi-factor authentication protections provided by FIDO2. The vulnerability is rated as high severity given the potential for complete authentication bypass.

Affected products

  • Delinea On-Premises Deployment

Related CVE's

  • CVE-2026-19117

Categories

  • Identity & Access
  • Zero-Day Vulnerabilities