CVE-2025-26788

HIGH

StrongKey FIDO Server <4.15.1 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2025-26788. PoCs published by EQSTLab, jun2e0.

AI-analyzed exploit summary This script automates the setup of StrongKey FIDO Server (SKFS) v4.15.0, including dependencies, configuration, and deployment of a basic demo application. It exploits CVE-2025-26788 by configuring a vulnerable environment for further exploitation.

Description

StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.

Exploits (2)

nomisec WORKING POC 1 stars
by EQSTLab · poc
https://github.com/EQSTLab/CVE-2025-26788

This script automates the setup of StrongKey FIDO Server (SKFS) v4.15.0, including dependencies, configuration, and deployment of a basic demo application. It exploits CVE-2025-26788 by configuring a vulnerable environment for further exploitation.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: StrongKey FIDO Server v4.15.0
No auth needed
Prerequisites: Root or sudo access on a Linux system with dnf package manager · Internet access to download dependencies and SKFS bundle
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by jun2e0 · poc
https://github.com/jun2e0/CVE-2025-26788

This repository provides a Docker-based environment setup for exploiting CVE-2025-26788, which targets StrongKey FIDO Server (SKFS) v4.15.0. It includes a Dockerfile, setup script, and instructions to deploy a vulnerable instance for testing.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: StrongKey FIDO Server (SKFS) v4.15.0
No auth needed
Prerequisites: Docker · Rocky Linux 9.3 · OpenLDAP · Java 21 · StrongKey FIDO Server v4.15.0
devstral-2 · analyzed May 13, 2026 Full analysis →

Scores

CVSS v3 8.4
EPSS 0.0041
EPSS Percentile 32.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-639
Status published
Products (1)
StrongKey/FIDO Server 4.10.0 - 4.15.1
Published Feb 14, 2025
Tracked Since Feb 18, 2026