Junglewise Threat Intelligence

CVE-2026-19611: WildFly Elytron password validation weakness via Unicode normalization

CVE-2026-19611 · Severity: high · CVSS 7.4 · Published 2026-08-20

Vendors: Red Hat.

Executive brief

WildFly Elytron is a security framework used in enterprise Java application servers to manage authentication and password verification. A flaw in its password normalization process allows attackers to bypass password security by using basic ASCII dictionary attacks against accounts with non-ASCII characters, potentially leading to unauthorized access and account compromise.

Technical details

The vulnerability stems from WildFly Elytron's use of Unicode NFKC normalization during password hashing and verification. NFKC normalization collapses fullwidth characters (such as full-width Latin or CJK variants) to their ASCII equivalents, reducing password entropy. An attacker with network access can perform offline dictionary attacks using ASCII-only passwords against accounts that were intended to have fullwidth or other non-ASCII characters, effectively lowering the security of such passwords. The flaw affects the password validation component during authentication. Patches are available from Red Hat.

Affected products

  • Red Hat WildFly Elytron

Timeline

  • 2026-08-20: disclosed

References

Related threats