A vulnerability, which was classified as problematic, was found in Symfony. The affected element is an unknown function of the component Cas2Handler. The manipulation results in authentication bypass by capture-replay.

This vulnerability is known as CVE-2026-45074. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component.