2.9
/ 10
LOW
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Description
Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.
Basic Information
ID
CVE-2026-40947
Source
mitre
Published
Apr 15, 2026 at 23:13
Modified
Apr 15, 2026 at 23:21
Affected Product
Vendor
Yubico
Product
libfido2
Affected Versions
Yubico libfido2 0
Yubico python-fido2 0
Yubico yubikey-manager 0
Yubico python-fido2 0
Yubico yubikey-manager 0