---
id: CVE-2026-72780
title: >-
  Craft CMS before 5.10.5 fails to persist updated credential counters after
  WebAuthn assertion validation in the passkey login endpoint
summary: >-
  Craft CMS before 5.10.5 fails to persist updated credential counters after
  WebAuthn assertion validation in the passkey login endpoint. Attackers can
  replay captured login request bodies containing requestOptions and response to
  create a…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-294
vendor: craftcms
product: cms
affected:
  - cms >= 5.0.0-RC1 < 5.10.5
published: '2026-08-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:34.640'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72780'
references:
  - url: 'https://github.com/craftcms/cms/security/advisories/GHSA-wg23-69c2-gjc8'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/craft-cms-before-webauthn-assertion-replay-via-login-with-passkey
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-11T18:04:35.322870Z'
epss: 0.00385
epssPercentile: 0.30377
ingestedAt: '2026-10-08T16:52:14.713Z'
---

## Overview

Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can replay captured login request bodies containing requestOptions and response to create additional authenticated sessions for victim accounts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
