{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/prowler/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Prowler (\u003c= 5.30.0)"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","saml","account-takeover","cloud-security","prowler"],"_cs_type":"advisory","_cs_vendors":["Prowler"],"content_html":"\u003cp\u003eProwler versions through 5.30.0 contain an improper authentication vulnerability (CWE-287) in the SAML authentication flow. The application incorrectly trusts the email domain asserted within a SAMLResponse to identify the target tenant for token issuance, rather than binding the token to the tenant associated with the validated SAML configuration. An attacker who has configured their own SAML identity provider (IdP) for their own tenant can forge SAML assertions to claim accounts in other tenants. Because the application uses a hardcoded auto-connect feature and allows IdP-initiated SSO, an attacker can bypass user interaction and trigger the vulnerable flow to obtain a JWT for a victim user. If successful, this grants the attacker full access to the victim's cloud security audit findings and enables lateral movement into other tenants through the token switch endpoint.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker configures a legitimate SAML identity provider for their own tenant on the target Prowler instance.\u003c/li\u003e\n\u003cli\u003eThe attacker triggers an IdP-initiated SSO flow against the target Prowler instance.\u003c/li\u003e\n\u003cli\u003eThe attacker presents a signed SAMLResponse to the ACS endpoint, specifying a \u003ccode\u003eNameID\u003c/code\u003e (email) belonging to a victim user in a different tenant (e.g., \u003ccode\u003euser@victim.com\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe Prowler SAML ACS finish logic parses the \u003ccode\u003euser.email\u003c/code\u003e from the assertion.\u003c/li\u003e\n\u003cli\u003eThe application code splits the email string to extract the domain, using it to look up the tenant in the database, ignoring the actual SAML configuration validated for the route.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003esociallogin.connect()\u003c/code\u003e method executes, linking the victim's existing account to the attacker's forged assertion.\u003c/li\u003e\n\u003cli\u003eThe system issues a temporary SAML token bound to the resolved (but incorrect) tenant.\u003c/li\u003e\n\u003cli\u003eThe attacker exchanges the SAML token for a JWT and utilizes the \u003ccode\u003etokens/switch\u003c/code\u003e endpoint to gain full access to the victim's actual tenant.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThis vulnerability allows for unauthorized cross-tenant account takeover. Successful exploitation grants an attacker full read/write access to all cloud security audit findings (AWS, GCP, Azure) within the victim's tenant. Additionally, attackers can enumerate, modify, or delete compliance findings, manipulate integration secrets, and leverage the token switch endpoint to pivot into any other tenants where the victim user maintains membership.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all Prowler instances to a patched version immediately once available from the maintainer.\u003c/li\u003e\n\u003cli\u003ePerform a manual review of all configured SAML configurations in the Prowler admin interface to identify unauthorized or suspicious domain mappings.\u003c/li\u003e\n\u003cli\u003eAudit system logs for unexpected or anomalous SAML authentication successes, specifically looking for \u003ccode\u003eACS\u003c/code\u003e requests originating from unknown IdP entity IDs.\u003c/li\u003e\n\u003cli\u003eImplement network-level restrictions on access to Prowler API endpoints if the instance is exposed to the public internet, limiting access to known corporate IP ranges until patching is complete.\u003c/li\u003e\n\u003cli\u003eReview the \u003ccode\u003eProwlerSocialAccountAdapter.pre_social_login\u003c/code\u003e logic in the codebase to ensure tenant binding is locked to the validated SAML configuration rather than the user email domain.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-12T00:57:02Z","date_published":"2026-09-12T00:57:02Z","id":"https://feed.craftedsignal.io/briefs/2026-09-prowler-saml-takeover/","summary":"Prowler versions through 5.30.0 contain an improper authentication vulnerability where the SAML ACS finish flow incorrectly derives the target tenant from an asserted email domain, enabling cross-tenant account takeover.","title":"Prowler SAML Domain Claiming Enables Cross-Tenant Account Takeover","url":"https://feed.craftedsignal.io/briefs/2026-09-prowler-saml-takeover/"}],"language":"en","title":"CraftedSignal Threat Feed - Prowler","version":"https://jsonfeed.org/version/1.1"}