---
id: CVE-2026-19611
title: A flaw was found in WildFly Elytron
summary: >-
  A flaw was found in WildFly Elytron. Password hashing and verification
  normalize input with Unicode NFKC, which can collapse fullwidth characters to
  ASCII equivalents. A remote attacker can more easily guess affected passwords
  by using a…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-173
vendor: Red Hat
product: wildfly-elytron-password-impl
affected:
  - wildfly-elytron-password-impl (all versions)
  - wildfly-elytron-password-impl (all versions)
  - keycloak/rhbk-openshift-rhel9 (all versions)
  - wildfly-elytron-password-impl (all versions)
  - wildfly-elytron-password-impl (all versions)
  - jboss-eap-7/eap74-els-openjdk17-openshift-rhel8 (all versions)
  - jboss-eap-7/eap74-els-openjdk8-openshift-rhel8 (all versions)
  - wildfly-elytron-password-impl (all versions)
  - wildfly-elytron-password-impl (all versions)
  - wildfly-elytron-password-impl
  - wildfly-elytron-password-impl (all versions)
published: '2026-08-20'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T18:17:07.910'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19611'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:69470'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-19611'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2514568'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
epss: 0.00345
epssPercentile: 0.27964
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-21T16:38:31.494304Z'
ingestedAt: '2026-09-21T17:49:53.182Z'
---

## Overview

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
