CRITICAL 9.3 NVD

CVE-2026-89042

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.

References

Published: 2026-09-10 · Source: NVD · Feed updated: 2026-09-12
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-10 via NVD.

Risk Timeline

CVE Disclosed2026-09-10 · 1 day ago

Remediation Resources

vulnfeed aggregates 12842 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.