MEDIUM

CVE-2026-4522

2026-06-25 CVSS v4.0
CVSS
6.7

Description

Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception.

This issue affects HYPR Passwordless: before 11.1.1.

Summary dbcve.org

HYPR Passwordless on Windows versions prior to 11.1.1 lack authentication checks on a critical function, enabling unauthenticated attackers to intercept credentials. This is a broken authentication vulnerability where the application fails to verify the caller's identity before allowing access to sensitive credential-handling operations.

Mitigation

Upgrade HYPR Passwordless to version 11.1.1 or later to implement proper authentication on the affected critical function.

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

0.18%
Probability of exploitation in next 30 days
7.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE