Tag
high
advisory
SimpleSAMLphp HTTP-Artifact Authentication Bypass via TLS Validator Confusion (CVE-2026-49283)
1 TTPA critical vulnerability (CVE-2026-49283) in SimpleSAMLphp's HTTP-Artifact receive path allows a malicious or lower-trust Identity Provider (IdP) to bypass authentication and impersonate users from a higher-trust IdP by leveraging a flaw where `SOAPClient::validateSSL()` fails to properly validate TLS public keys for unsigned SAML Responses.
SimpleSAMLphp SAML2 +3
vulnerability
saml
authentication-bypass
identity-federation
1t
high
advisory
AWS SAML Identity Provider Update Detection
2 rules 1 TTPDetection of unauthorized updates to AWS SAML identity providers using CloudTrail logs, potentially indicating compromised federated credentials and unauthorized access.
AWS Identity and Access Management
aws
saml
identity-federation
cloud
2r
1t