Executive brief
HYPR Passwordless for Windows is a security solution designed to replace traditional passwords with secure, biometric-based logins. A vulnerability in versions prior to 11.1.1 allows for the interception of user credentials because a critical internal function does not properly verify the user's identity. This could allow an attacker with local access to the machine to steal sensitive login information, potentially compromising the user's account and corporate access.
Technical details
A missing authentication for critical function vulnerability exists in HYPR Passwordless for Windows versions prior to 11.1.1. The flaw resides in a component that handles sensitive credential operations without sufficient identity verification. An attacker with local access to the Windows operating system could exploit this lack of authentication to intercept user credentials during the login or authentication process. This is classified as a credential interception risk. The issue has been remediated in version 11.1.1, and users are advised to upgrade to the latest version to mitigate the risk.
Affected products
- HYPR Passwordless for Windows before 11.1.1
Timeline
- 2026-06-25: advisory: NVD publication date
- 2026-06-25: patched: Fix version 11.1.1 listed in vendor advisory