CVE-2026-19611

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-20 16:17

Updated : 2026-09-03 18:17


NVD link : CVE-2026-19611

Mitre link : CVE-2026-19611

CVE.ORG link : CVE-2026-19611


JSON object : View

Products Affected

No product.

CWE
CWE-173

Improper Handling of Alternate Encoding