Junglewise Threat Intelligence

CVE-2026-33585: Arqit SKA-Platform improper idle timeout management in Keycloak interface

CVE-2026-33585 · Severity: low · CVSS 3.8 · Published 2026-05-13

Technologies: Arqit Symmetric Key Agreement Platform. Vendors: Arqit.

Executive brief

The Arqit Symmetric Key Agreement Platform (SKA-Platform) contains a security flaw where user sessions do not expire as expected. This platform is used for secure cryptographic key management, and this specific issue allows an unauthorized person with physical access to a workstation to hijack an active user session. This could lead to unauthorized access to the management interface and potential impersonation of legitimate users.

Technical details

The vulnerability is caused by improper handling of parameters (CWE-233) within the Keycloak interface of the Arqit SKA-Platform. Specifically, the tenant web management interface ignores the session idle timeout values defined in Keycloak. An attacker with physical access to a victim's machine can exploit this by utilizing an unexpired browser session that should have been terminated. This allows for the impersonation of an authenticated tenant user. The issue is fixed in version 26.03.

Affected products

  • Arqit Symmetric Key Agreement Platform (SKA-Platform) 25.09.x, 25.12, and all versions before 26.03

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory

References

Related threats