HYPR Security Advisories

To report a security concern please see HYPR Vulnerability Disclosure

HYPR software routinely undergoes security assessments in order to identify any potential security risks. As a result of these internal and external efforts some vulnerabilities may be identified and proper advisories are sent when remediation is available.

You can find here a list of risks identified in the HYPR components.

CVE ID

Risk

Affected Version

Fix Version

Description

Component

CVE-2026-4522

Medium

<11.1.1

11.1.1

Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception.


HYPR thanks Federico Bento (Blaze Information Security) for this report.

HYPR Passwordless for Windows

CVE-2026-2414

High

9.5.2 to 10.7.2

10.7.3

Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.

HYPR Server

CVE-2026-1712

High

10.5.x

10.7

Incorrect privilege assignment vulnerability in HYPR Server allows Privilege Escalation.

HYPR Server

CVE-2025-2102

Medium

<10.1

10.1

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.

HYPR Passwordless for Windows

CVE-2025-0372

Medium

<10.1

10.1

Race Condition vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.

HYPR Passwordless for Windows

CVE-2024-8273

High

<10.1

10.1

Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.

HYPR Server

CVE-2024-1721

Medium

<9.1

9.1

Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.


HYPR thanks r31n for this report.

HYPR Passwordless for Windows

CVE-2024-0068

Medium

<8.7.1

8.7.1

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.

HYPR Mac WFA

CVE-2023-6336

High

<8.7

8.7

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filename.

HYPR Mac WFA

CVE-2023-6335

Medium

<8.7

8.7

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.

HYPR Windows WFA

CVE-2023-6334

Medium

<8.7

8.7

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Buffers.


HYPR thanks r31n for this report.

HYPR Windows WFA

CVE-2023-5097

High

<8.7

8.7

Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.


HYPR thanks r31n for this report.

HYPR Windows WFA

CVE-2023-1837

High

<8.0

8.0

Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.


This issue affects HYPR Server before 8.0 with enabled Legacy APIs.

HYPR Server

CVE-2023-1477

High

<7.10.2

<8.0.3

7.10.2

8.0.3

Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.


HYPR thanks Matthew Rogers for this report.

HYPR Keycloak Authenticator Extension

CVE-2023-0834

High

<8.1

8.1

Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.


HYPR thanks Miguel Silva (Blaze Information Security) for this report.

HYPR Mac WFA

CVE-2022-3258

Low

<7.7.1

7.7.1

Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse.

HYPR Windows WFA

CVE-2022-1984

Medium

<7.3

7.3

Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before version 7.3 may allow local authenticated attackers to elevate privileges via a malicious serialized payload.

HYPR Windows WFA

CVE-2022-2192

High

6.10 to 6.15.1

6.15.2

Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate privileges via path tampering in the Magic Link page.

HYPR Server

CVE-2022-2193

High

<6.14.1

6.14.1

Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authenticator to arbitrary accounts via parameter tampering in the Device Manager page.

HYPR Server