Junglewise Threat Intelligence

CVE-2026-72780: Craft CMS WebAuthn assertion replay in passkey login

CVE-2026-72780 · Severity: medium · CVSS 6.5 · Published 2026-08-11

Technologies: Craft CMS, craftcms/cms (Packagist). Vendors: Packagist.

Executive brief

Craft CMS's passkey login feature fails to properly validate replay protection, allowing attackers to reuse captured login requests to create additional authenticated sessions for victim accounts. If an attacker obtains a single successful login request (which could happen through application logs, debugging proxies, or similar exposure), they can replay it multiple times to gain unauthorized access to the victim's account without needing the actual passkey device.

Technical details

Craft CMS's passkey login endpoint (/actions/users/login-with-passkey) accepts WebAuthn requestOptions from unauthenticated user input and fails to persist the updated credential counter after assertion validation. The vulnerability is a capture-replay flaw (CWE-294): the system accepts the same requestOptions and response multiple times, allowing the attacker to validate assertions against stale credential counters. An attacker with a captured login request body containing requestOptions and response can repost it to the endpoint, bypassing WebAuthn's challenge-response and replay-counter protections. The vulnerability affects Craft CMS versions 5.0.0-RC1 through 5.10.4; version 5.10.5 and later persist updated credential sources to prevent replay attacks. No authentication is required to trigger the replay, only possession of the previously-captured request body.

Affected products

  • Craft CMS 5.0.0-RC1 to before 5.10.5

Timeline

  • 2026-07-25: disclosed: GitHub Security Advisory GHSA-wg23-69c2-gjc8 published
  • 2026-08-11: patched: Craft CMS 5.10.5 released with fix
  • 2026-08-11: advisory: CVE-2026-72780 published on NVD

References

Related threats