CVE-2026-33583 Details
Description
Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via an unauthenticated and unencrypted HTTP GET method in the Arqit Symmetric Key Agreement Platform. This issue affects Symmetric Key Agreement Platform: before 26.03.
A vulnerability in the Arqit Symmetric Key Agreement Platform prior to version 26.03 allows for the unauthenticated and unencrypted exposure of the QKEY used in the 'OTA-Quantum' device registration process, as well as internal system keys. This exposure occurs through a REST API that can be accessed via an HTTP GET method, enabling network attackers to retrieve sensitive cryptographic keys from the platform's database.
Users can upgrade to Arqit Symmetric Key Agreement Platform version 26.03 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 13, 2026CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cvcn.gov.it/cvcn/cve/CVE-2026-33583 | ENISA | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-749 | Exposed Dangerous Method or Function | ENISA |
Affected Products
| Product | Versions |
|---|---|
| Arqit Symmetric Key Agreement Platform | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ENISA |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | New CVE Received | ENISA |
Volerion