{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/passport-saml-encrypted--0.1.13/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:passport-saml-encrypted:passport-saml-encrypted:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-89042"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["passport-saml-encrypted (\u003c= 0.1.13)"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","saml","supply-chain","vulnerability","cve-2026-89043"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-89042 affects the passport-saml-encrypted library through version 0.1.13. The vulnerability stems from an insecure implementation of SAML signature verification logic, where the library makes the verification process conditional based on an optional 'cert' configuration parameter. When this parameter is absent or misconfigured, the library fails to validate the signature of the SAML response. This design flaw allows a remote, unauthenticated attacker to inject forged SAML responses directly into the application's Assertion Consumer Service (ACS) endpoint. By providing an unsigned assertion containing arbitrary 'NameID' fields and malicious user attributes, the attacker can successfully impersonate any user within the target system, bypassing primary authentication mechanisms. The severity is elevated due to the ease of exploitation and the direct impact on system-wide access control.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full authentication bypass, leading to unauthorized account access and potential privilege escalation within applications utilizing this library. The vulnerability affects any service relying on passport-saml-encrypted for SAML-based identity federation. Given the nature of SAML assertions, an attacker can craft assertions to match any existing user ID, posing a severe risk to multi-tenant or enterprise environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch immediately by upgrading the passport-saml-encrypted dependency to a version higher than 0.1.13.\u003c/li\u003e\n\u003cli\u003eAudit all application configurations utilizing this library to ensure that the optional 'cert' validation parameter is explicitly enabled and properly configured.\u003c/li\u003e\n\u003cli\u003eReview application authentication logs for anomalous SAML response submissions that lack corresponding signature metadata or originate from unexpected sources.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-10T21:08:24Z","date_published":"2026-09-10T19:07:39Z","id":"https://feed.craftedsignal.io/briefs/2026-09-passport-saml-bypass/","summary":"The passport-saml-encrypted library versions up to 0.1.13 contain a critical vulnerability where SAML signature verification is skipped if a specific configuration is omitted, allowing attackers to forge and inject arbitrary authentication assertions.","title":"Authentication Bypass in passport-saml-encrypted via Unsigned SAML Assertions","url":"https://feed.craftedsignal.io/briefs/2026-09-passport-saml-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Passport-Saml-Encrypted (\u003c= 0.1.13)","version":"https://jsonfeed.org/version/1.1"}