Junglewise Threat Intelligence

CVE-2026-0872: Thales SafeNet Agent for Windows Logon certificate validation spoofing

CVE-2026-0872 · Severity: info · Published 2026-02-13

Executive brief

Thales SafeNet Agent for Windows Logon is an authentication component that secures Windows system access. A certificate validation flaw allows attackers to spoof digital signatures, potentially bypassing authentication and gaining unauthorized system access without valid credentials.

Technical details

This vulnerability involves improper certificate validation in the SafeNet Agent for Windows Logon authentication component. The flaw allows attackers to forge or spoof digital signatures by circumventing certificate validation checks, potentially leading to authentication bypass. An attacker would need to be in a position to intercept or manipulate the authentication flow (network or local access). The vulnerability affects versions 4.0.0, 4.1.1, and 4.1.2. Patches or updated versions should be available from Thales support.

Affected products

  • Thales SafeNet Agent for Windows Logon 4.0.0, 4.1.1, 4.1.2

Timeline

  • 2026-02-13: disclosed

References