CVE-2026-33585Disclosure

LOWCVSS 3.8 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-233

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-13: 2Technical Details · 2026-05-13: 205-13
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33585 Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user … https://www.cve.org/CVERecord?id=CVE-2026-33585

    Post summary

    The post announces CVE‑2026‑33585, noting that mismanagement of the idle timeout in Keycloak can allow attackers to impersonate authenticated tenant users, with no PoC, exploit, active hacking evidence, or patch provided.

    00000201
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33585 Session Impersonation in Arqit SKA-Platform Keycloak Interface Before 26.03 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33585

    Post summary

    CVE-2026-33585 is a newly disclosed vulnerability that allows session impersonation in the Arqit SKA-Platform Keycloak Interface before version 26.03, with no proof‑of‑concept, exploit, or patch information provided.

    0000046
    4.0K followersView on X

Explore more