Security Advisory

CVE-2026-33585

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-13 18:46:13
Last updated 2026-05-13 19:31:17
Assigner ENISA
CVSS score 3.8
State PUBLISHED

Description

Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03.