HYPR Corp develops a portfolio of passwordless authentication and workforce-access management products, positioned as identity and access control solutions across enterprise deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including improper link resolution, authorization and authentication bypass flaws, permission misconfigurations, and buffer overflows—patterns that reflect both the authentication-layer role these products play and underlying memory-safety challenges in their implementation. Defenders should treat authentication and access-control products from this vendor as sensitive to remediation timelines, and track the recurring authorization and authentication classes closely; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by HYPR Corp over time
Of all the CVEs published by HYPR Corp as a CNA, 73.7% affect products that HYPR Corp develops as a vendor.
Of all the CVEs published that affect products developed by HYPR Corp, 100.0% are self-published by HYPR Corp as a CNA.
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2414CRITICAL Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue affects Server: from 9.5.2 before 10.7.2. | Mar 25, 2026 | 9.8 | 29 | NO | NO |
CVE-2022-3258HIGH Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse. | Nov 3, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-8273HIGH Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: before 10.1. | Dec 11, 2025 | 8.8 | 27 | NO | NO |
CVE-2023-0834CRITICAL Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issue affects Workforce Access: from 6.12 bef | Apr 28, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-1837HIGH Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.This issue affects HYPR Server: before 8.0 (with enabl | May 23, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-1477HIGH Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak Authenticator Extension: before 7.10.2, | Apr 28, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-2193HIGH Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authenticator to arbitrary accounts via par | Jul 19, 2022 | 8.8 | 24 | NO | NO |
CVE-2023-6336HIGH Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filename.This issue affects Workforce Access: | Jan 16, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-6335HIGH Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This issue affects Workforce Access | Jan 16, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-6334HIGH Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Buffers.This issue affects Workforce Acces | Jan 16, 2024 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by HYPR Corp.
Media articles that mention a CVE ID that affects a product developed by HYPR Corp — matched by CVE ID, not by vendor name.