CVE-2026-19117
FIDO2 Credential Registration Vulnerability Allows Account Takeover
Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.
An attacker can register a malicious FIDO2 credential against a target account in on-premises deployments, enabling them to authenticate as that user and gain unauthorized access. This bypasses standard authentication controls.