CVE-2026-19117
moderateFIDO2 credential enrollment auth bypass in Okta on-prem deployments
CVE-2026-19117 is an authentication flaw (CWE-290, authentication bypass by spoofing) affecting Okta on-premises deployments, in which an attacker can register an attacker-controlled FIDO2 credential against a target user's account under specific conditions. Per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N), it is remotely exploitable without privileges, user interaction, or authentication. Once the credential is registered, the attacker authenticates as that user with their own authenticator, achieving a full account takeover with high confidentiality, integrity, and availability impact (9.8 Critical). Only on-premises deployments are affected; cloud/SaaS customers are not impacted by this issue. No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is currently known, and EPSS is 0.3% (21st percentile).
What to do: Consult the Okta security advisory for CVE-2026-19117 to identify the exact affected product and patched release, then upgrade all on-premises deployments as soon as a fixed version is available. Until patched, limit internet exposure of the affected FIDO2 enrollment/authentication endpoints and audit user accounts for FIDO2 credentials that were not enrolled by the legitimate owner, removing any suspicious ones. Re-check exploitation signals (EPSS, KEV, vendor bulletins) periodically, since no in-the-wild exploitation is currently known.
| Okta | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.
- Weakness
- CWE-290
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.