Impact
Craft CMS before version 5.10.5 does not update credential counters after validating WebAuthn assertions in the passkey login flow. An attacker who has captured a login request body that includes requestOptions and the corresponding response can reuse that capture to obtain additional authenticated sessions for the victim’s account, effectively bypassing the intended security check. This flaw enables attackers to impersonate a user and establish unauthorized sessions without initial authentication.
Affected Systems
The affected product is Craft CMS (craftcms:cms) running any version prior to 5.10.5. Users with earlier releases are vulnerable to replay attacks that may allow access to restricted content and settings.
Risk and Exploitability
The CVSS score of 7.1 indicates substantial risk. Although the EPSS value is not available, the absence of an entry in the CISA KEV catalog suggests no publicly known exploit has been observed yet, but the flaw remains serious. Exploitation requires an attacker to capture a WebAuthn assertion – typically by compromising the victim’s device or monitoring network traffic – and then replay the request. This path is feasible for an adversary with privileged access to the session or the ability to intercept authentication traffic, but it is not trivially automated for every target.
OpenCVE Enrichment