CVE-2026-33584 PUBLISHED

Arqit SKA-Platform Enables Access to Debug Information

Assigner: ENISA
Reserved: 23.03.2026 Published: 13.05.2026 Updated: 13.05.2026

Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensitive debug information such as metrics and health data. This issue affects Symmetric Key Agreement Platform: before 26.03.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 5.3

Product Status

Vendor Arqit
Product Symmetric Key Agreement Platform
Versions Default: unaffected
  • affected from 0 to 26.03 (excl.)

References

Problem Types

  • CWE-749 Exposed dangerous method or function CWE