CVE-2026-89042
passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypas
CVSS
9.1
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 10 sept 2026 · Última mod.: 10 sept 2026 · CWE-347
Sin historial EPSS suficiente todavía.
passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.
- github.comhttps://github.com/krakenjs/passport-saml-encrypted
- github.comhttps://github.com/krakenjs/passport-saml-encrypted/blob/v0.1.13/lib/saml.js#L296
- github.comhttps://github.com/krakenjs/passport-saml-encrypted/blob/v0.1.13/lib/saml.js#L321
- github.comhttps://github.com/krakenjs/passport-saml-encrypted/issues/29
- www.vulncheck.comhttps://www.vulncheck.com/advisories/passport-saml-encrypted-through-0.1.13-authentication-bypass-via-missing-signature-verification
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-890869.1 CRÍ—
———In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.10hCVE-2026-890437.4 ALT—
———passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SAML message can prepend a forged unsigned assertion that gets accepted as the verified identity while the genuine signature validates against the original assertion.11hCVE-2023-543557.5 ALT—
——0PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginPacket uses the required secp384r1 elliptic curve. Attackers can provide LoginPackets with keys using different curves or non-EC key types to pass login verification but trigger an uncaught exception during ECDH key derivation, crashing the server.16hCVE-2026-799705.6 MED—
——0Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.1dCVE-2026-562079.8 CRÍ—
——0Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user.
This issue affects Apache Impala: >=4.0.0.
Users are recommended to upgrade to version 4.5.2, which fixes this issue.10hCVE-2026-877326.2 MED0.1%
——0An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then compares the tag. On a forged tag, the functions returns false, but the destination buffer already holds the full plaintext.2d