MEDIUM
CVE-2026-4522
CVSS
6.7
Description
Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception.
This issue affects HYPR Passwordless: before 11.1.1.
Summary dbcve.org
HYPR Passwordless on Windows versions prior to 11.1.1 lack authentication checks on a critical function, enabling unauthenticated attackers to intercept credentials. This is a broken authentication vulnerability where the application fails to verify the caller's identity before allowing access to sensitive credential-handling operations.
Mitigation
Upgrade HYPR Passwordless to version 11.1.1 or later to implement proper authentication on the affected critical function.
Weakness (CWE)
CWE-306
Missing Authentication
EPSS Score
0.18%
Probability of exploitation in next 30 days
7.7th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.