Junglewise Threat Intelligence

CVE-2026-33583: Arqit Symmetric Key Agreement Platform sensitive key exposure

CVE-2026-33583 · Severity: high · CVSS 8.7 · Published 2026-05-13

Technologies: Arqit Symmetric Key Agreement Platform. Vendors: Arqit.

Executive brief

The Arqit Symmetric Key Agreement Platform, which manages secure cryptographic keys for device registration, contains a vulnerability that exposes sensitive security keys. An attacker can access these keys without a password because they are transmitted over an insecure, unencrypted connection. This could allow an unauthorized party to intercept internal system keys and compromise the security of the entire device registration process.

Technical details

The Arqit Symmetric Key Agreement (SKA) Platform exposes a REST API that allows for the retrieval of cryptographic keys from the system database. The vulnerability is classified as an exposed dangerous method (CWE-749) because the 'Qkey' service is accessible via unauthenticated and unencrypted HTTP GET requests. A network-based attacker can exploit this to retrieve the QKEY—used in the 'OTA-Quantum' device registration process—and other internal system keys. While the attack complexity is rated high, successful exploitation results in a complete loss of confidentiality and integrity for the affected cryptographic material. The issue is resolved in version 26.03.

Affected products

  • Arqit Symmetric Key Agreement Platform before 26.03 (specifically 25.09.x and 25.12)

Timeline

  • 2026-05-13: advisory: NVD and ENISA published the vulnerability details.
  • 2026-05-13: patched: Version 26.03 identified as the fixed version.

References

Related threats