CVE-2026-86304CWE-347

CVE-2026-86304

published September 7, 2026

CVSS
EPSS
In the wild
Unconfirmed
What it is

MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor.

parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no cacert, cert_text or anchors argument, then passes the returned XML to Net::SAML2::Protocol::Assertion->new_from_xml with the IdP signing certificate as cacert. In Net::SAML2 before 0.86 that certificate guards only encrypted assertions, so the signature on an unencrypted assertion is checked against the certificate the response itself carries.

An attacker starts a SAML login, then posts a response signed with a certificate of their own. The audience, InResponseTo and timestamp checks that follow are all satisfiable by the attacker, so the response authenticates any NameID it carries.

The record
Technical detail
CVSS
Not scored
CVSS v4.0
Not supplied
EPSS
Not scored
Weakness
CWE-347 · Improper Verification of Cryptographic Signature
Published
2026-09-07T03:17Z
References (3)
Timeline
  • 06 SEP 22:24Z
    MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor
    cvelistv5