CRITICALVulnerability

CVE-2026-89042

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.

Properties

severity
CRITICAL
score
9.1
cve_id
CVE-2026-89042
signal_observed_at
2026-09-18T13:45:43+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
published_at
2026-09-10T18:18:15.910
last_modified
2026-09-11T21:17:56.573

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Verification of Cryptographic Signature

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-89042 — Ninja Signal Threat Intelligence | Ninja Signal