CVE-2026-86304

MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no cacert, cert_text or anchors argument, then passes the returned XML to Net::SAML2::Protocol::Assertion->new_from_xml with the IdP signing certificate as cacert. In Net::SAML2 before 0.86 that certificate guards only encrypted assertions, so the signature on an unencrypted assertion is checked against the certificate the response itself carries. An attacker starts a SAML login, then posts a response signed with a certificate of their own. The audience, InResponseTo and timestamp checks that follow are all satisfiable by the attacker, so the response authenticates any NameID it carries.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-06 23:17

Updated : 2026-09-08 19:20


NVD link : CVE-2026-86304

Mitre link : CVE-2026-86304

CVE.ORG link : CVE-2026-86304


JSON object : View

Products Affected

No product.

CWE
CWE-347

Improper Verification of Cryptographic Signature