CVE-2026-33585: Arqit Symmetric Key Agreement Platform
Low severity, CVSS 3.8. EPSS: 0.1% chance of exploitation in the next 30 days.
Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03.
Affected products
- Arqit Symmetric Key Agreement Platform: before 26.03 (fixed in 26.03)
Published 2026-05-13. Last modified 2026-06-17.