### [CVE-2025-26788](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-26788) ![](https://img.shields.io/static/v1?label=Product&message=FIDO%20Server&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=4.10.0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-639%20Authorization%20Bypass%20Through%20User-Controlled%20Key&color=brightgreen) ### Description StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction. ### POC #### Reference - https://www.securing.pl/en/cve-2025-26788-passkey-authentication-bypass-in-strongkey-fido-server/ #### Github - https://github.com/EQSTLab/CVE-2025-26788 - https://github.com/PuddinCat/GithubRepoSpider - https://github.com/nomi-sec/PoC-in-GitHub