Vulnerabilities in WebAuthn Standard Implementations

Authors

  • Sven Ulčar University of Ljubljana, Faculty of Computer and Information Science
  • Matevž Pesek University of Ljubljana, Faculty of Computer and Information Science https://orcid.org/0000-0001-9101-0471

DOI:

https://doi.org/10.31449/upinf.293

Keywords:

WebAuthn, FIDO2, credential binding, authentication vulnerability, demonstration implementation

Abstract

The WebAuthn standard enables passwordless authentication using asymmetric cryptography and addresses several well-known vulnerabilities of traditional password-based authentication. Despite the formally proven security of the standard itself, practical implementations often contain server-side flaws that allow authentication bypass. This article addresses the vulnerability of incorrect credential binding to a user account, which allows an attacker to take over another user's account using their own valid credential. A review of four CVE vulnerabilities from 2025 and 2026 shows that server-side flaws recur in credential binding, cryptographic challenge handling, and origin validation. An intentionally vulnerable demonstration application and its patched version were developed: the attack bypasses authentication on the vulnerable version and is rejected on the patched one. A comparison of four widely-used libraries shows that three leave credential binding to the application, while one requires it at the interface level. The analysis yields developer guidelines, among them strict credential-to-user binding. The security of WebAuthn-based systems is not an automatic consequence of library or language choice, but requires explicit server-side verification of credential ownership.

Author Biographies

  • Sven Ulčar, University of Ljubljana, Faculty of Computer and Information Science

    Sven Ulčar is a student at the Faculty of Computer and Information Science, University of Ljubljana. His interests include cybersecurity and systems infrastructure.

  • Matevž Pesek, University of Ljubljana, Faculty of Computer and Information Science

    Matevž Pesek is an associate professor and researcher at the Faculty of Computer and Information Science, University of Ljubljana, where he received his B.Sc. (2012) and Ph.D. (2018). He has been a member of the Computer Graphics and Multimedia Laboratory since 2009. Since 2024, he teaches Program Security and System Security courses, focusing his research on teaching concepts and organizing events in the field of computer security.

Published

2026-09-15

Issue

Section

Professional papers

How to Cite

[1]
2026. Vulnerabilities in WebAuthn Standard Implementations. Applied Informatics. (Sept. 2026). DOI:https://doi.org/10.31449/upinf.293.

Most read articles by the same author(s)

1 2 > >>