CVE-2026-4522: Hypr Passwordless

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception. This issue affects HYPR Passwordless: before 11.1.1.

Affected products

  • Hypr Passwordless: before 11.1.1 (fixed in 11.1.1)

Published 2026-06-25. Last modified 2026-06-25.