ZeroHour

CVE-2026-19117

moderate

FIDO2 credential enrollment auth bypass in Okta on-prem deployments

CVSS 3.1
9.8 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-19117 is an authentication flaw (CWE-290, authentication bypass by spoofing) affecting Okta on-premises deployments, in which an attacker can register an attacker-controlled FIDO2 credential against a target user's account under specific conditions. Per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N), it is remotely exploitable without privileges, user interaction, or authentication. Once the credential is registered, the attacker authenticates as that user with their own authenticator, achieving a full account takeover with high confidentiality, integrity, and availability impact (9.8 Critical). Only on-premises deployments are affected; cloud/SaaS customers are not impacted by this issue. No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is currently known, and EPSS is 0.3% (21st percentile).

What to do: Consult the Okta security advisory for CVE-2026-19117 to identify the exact affected product and patched release, then upgrade all on-premises deployments as soon as a fixed version is available. Until patched, limit internet exposure of the affected FIDO2 enrollment/authentication endpoints and audit user accounts for FIDO2 credentials that were not enrolled by the legitimate owner, removing any suspicious ones. Re-check exploitation signals (EPSS, KEV, vendor bulletins) periodically, since no in-the-wild exploitation is currently known.

Affected
Okta
Estimated exposure
moderate~10,000–100,000 end users across on the order of 1,000–10,000 on-premises deployments (estimated; Okta's much larger SaaS user base is unaffected) — Okta's reported customer base of roughly 18,000 is overwhelmingly cloud/SaaS, and only a minority of customers run its on-premises components (e.g., Access Gateway/Identity Gateway-style deployments), implying a low-thousands deployment…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

Weakness
CWE-290
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.