{"id":"CVE-2021-38299","aliases":["GHSA-6whf-q6p5-84wg"],"url":"https://o3.security/vulnerability/CVE-2021-38299","summary":"Improper Access Control in Webauthn Framework","details":"Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.","published":"2021-09-27T06:15:07.910Z","modified":"2026-08-07T16:57:50.127923Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"web-auth/webauthn-framework","fixedVersion":"3.3.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/web-auth/webauthn-framework/releases"},{"type":"ADVISORY","url":"https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2021-1-fehlende-ueberpruefung-von-user-presence-in-webauthn-framework/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T16:57:50.127923Z"}}