A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.
History

Fri, 27 Feb 2026 08:30:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.
Title org.keycloak/keycloak-services: WebAuthn Attestation Statement Verification Bypass Org.keycloak/keycloak-services: webauthn attestation statement verification bypass
First Time appeared Redhat
Redhat build Keycloak
Weaknesses CWE-347
CPEs cpe:/a:redhat:build_keycloak:26.2::el9
cpe:/a:redhat:build_keycloak:26.4::el9
Vendors & Products Redhat
Redhat build Keycloak
References

Wed, 29 Oct 2025 00:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title org.keycloak/keycloak-services: WebAuthn Attestation Statement Verification Bypass
Weaknesses CWE-302
CWE-304
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}

threat_severity

Low


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-02-27T08:10:15.448Z

Reserved: 2025-10-24T11:44:03.633Z

Link: CVE-2025-12150

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-27T09:16:15.227

Modified: 2026-02-27T14:06:37.987

Link: CVE-2025-12150

cve-icon Redhat

Severity : Low

Publid Date: 2025-10-28T15:04:00Z

Links: CVE-2025-12150 - Bugzilla