CVE-2026-75800

The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-12 06:16

Updated : 2026-09-14 21:10


NVD link : CVE-2026-75800

Mitre link : CVE-2026-75800

CVE.ORG link : CVE-2026-75800


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication