In eduMFA < 2.9.1 userless Passkey/WebAuthn challenges might be replayed and do not expire
Fixed in eduMFA >= 2.9.1 by adding validity information to the userless challenges.
No known workarounds besides disabling userless login altogether.
{
"cwe_ids": [
"CWE-287",
"CWE-613"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-18T15:37:00Z",
"nvd_published_at": null,
"severity": "HIGH"
}