CVE-2026-89042
passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- CWE
- CWE-347
- Published
- 2026-09-10
- Last modified
- 2026-09-10
Affected products
- krakenjs passport-saml-encrypted
Weakness type
Related vulnerabilities
- CVE-2026-89086 — In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only...
- CVE-2026-89043 — passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending
- CVE-2023-54355 — PocketMine-MP 5.2.0 Server Crash via Incorrect EC Curve
- CVE-2026-79970 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-56207 — Apache Impala: SAML authentication bypass via forged bearer token
- CVE-2026-87732 — An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The...
- CVE-2026-86080 — n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
- CVE-2026-69646 — Skype for Business Spoofing Vulnerability