CVE-2026-33585 Details
Description
Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03.
A vulnerability exists in the Arqit SKA-Platform's Keycloak interface, specifically in versions prior to 26.03. The issue arises from improper handling of the idle timeout parameter, which allows an attacker to impersonate an authenticated tenant user by exploiting an unexpired browser session.
Users can upgrade to Arqit SKA-Platform version 26.03 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 13, 2026CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cvcn.gov.it/cvcn/cve/CVE-2026-33585 | ENISA | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-233 | Improper Handling of Parameters | ENISA |
Affected Products
| Product | Versions |
|---|---|
| Arqit SKA-Platform | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ENISA |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | New CVE Received | ENISA |
Volerion