CVE-2025-26788: Strongkey Fido Server

High severity, CVSS 8.4. EPSS: 0.5% chance of exploitation in the next 30 days.

StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.

Affected products

  • Strongkey Fido Server: from 4.10.0, before 4.15.1 (fixed in 4.15.1)

Published 2025-02-14. Last modified 2026-06-17.