CVE-2024-31498: Yubico Yubikey Manager GUI

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Yubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation because browser windows can open as Administrator.

Affected products

  • Yubico Yubikey Manager GUI: before 1.2.6 (fixed in 1.2.6)

Published 2024-04-04. Last modified 2026-06-17.