Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-89042

Опубликовано: 10 сент. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.

EPSS

Процентиль: 20%
0.00271
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 9.1
github
13 дней назад

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.

EPSS

Процентиль: 20%
0.00271
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-347