3.8
/ 10
LOW
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Description
Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session.
This issue affects Symmetric Key Agreement Platform: before 26.03.
This issue affects Symmetric Key Agreement Platform: before 26.03.
Basic Information
ID
CVE-2026-33585
Source
ENISA
Published
May 13, 2026 at 18:46
Modified
May 13, 2026 at 19:31
Affected Product
Vendor
Arqit
Product
Symmetric Key Agreement Platform
Affected Versions
Arqit Symmetric Key Agreement Platform 0