Yubico Software Vulnerability Allows Code Injection via DLL Path Flaw

Yubico Software Vulnerability Allows Code Injection via DLL Path Flaw

First seen 17 Apr 2026, 17:31 UTC Heise.Dewww.yubico.comnvd.nist.govsupport.microsoft.comdevelopers.yubico.com+1 93% similarity 64.5

Article Content

Browse articles
ThreatCluster

A security vulnerability affecting YubiKey Manager, libfido2, and python-fido2 has been identified, allowing attackers to execute injected code on Windows systems. The flaw arises from improper DLL path handling, specifically the use of LoadLibrary(TEXT('DLL_NAME')), which does not restrict paths to the System32 directory. If an attacker can place a malicious file in the installation directory of the affected software, they can execute arbitrary code. Yubico has released updated software versions to address this issue, which include libfido2 1.17.0, python-fido2 2.2.0, and yubikey-manager 5.9.1. The vulnerability has been assigned CVE-2026-40947 and carries a CVSS score of 7.0, indicating a high risk. While Yubico assesses the vulnerability as high risk, MITRE has classified it as low risk with a CVSS score of 2.9. Users are advised to update their software to mitigate the risk. No Yubico hardware is affected by this vulnerability.

Key Points: • A DLL path vulnerability allows code execution in YubiKey Manager and related software. • Yubico has released patches for affected software versions to close the security gaps. • CVE-2026-40947 is rated high risk by Yubico with a CVSS score of 7.0.

ThreatCluster AI How this analysis works

Timeline

2026-04-15
CVE-2026-40947 published
2026-04-17
Yubico releases patches for affected software

Community

Browse all →

Tracked Entities in This Story