CVE-2026-89042

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-10 18:18

Updated : 2026-09-11 21:17


NVD link : CVE-2026-89042

Mitre link : CVE-2026-89042

CVE.ORG link : CVE-2026-89042


JSON object : View

Products Affected

No product.

CWE
CWE-347

Improper Verification of Cryptographic Signature