CVE-2026-33585CWE-233

Arqit SKA-Platform Improper Handling of Parameters Vulnerability

Low · published May 13, 2026

CVSS v3.1
3.8
EPSS
0%
Percentile
3.2
In the wild
Unconfirmed
What it is

Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session.

This issue affects Symmetric Key Agreement Platform: before 26.03.

The record
Technical detail
CVSS v3.1
3.8 · LOW
Vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
CVSS v4.0
Not supplied
EPSS
0.00134 · 3.2th percentile
Weakness
CWE-233 · Improper Handling of Parameters
Published
2026-05-13T18:46Z
EPSS history
Timeline
  • 13 MAY 18:46Z
    Arqit SKA-Platform Improper Handling of Parameters Vulnerability
    cvelistv5