Beveiligingsadvies

CVE-2026-33585

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-13 18:46:13
Laatst bijgewerkt 2026-05-13 19:31:17
Toegewezen door ENISA
CVSS-score 3.8
Status PUBLISHED

Beschrijving

Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03.