CVE-2026-18092

Source
https://cve.org/CVERecord?id=CVE-2026-18092
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18092.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-18092
Published
2026-08-03T13:24:52.137Z
Modified
2026-08-08T03:30:15.588064060Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H CVSS Calculator
Summary
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree
Details

Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because newfromxml reads assertion identity with document-wide XPath instead of the signed subtree.

newfromxml reads the NameID, attribute values, SessionIndex, audience and other identity fields with document-wide XPath, such as //saml:Assertion/saml:AttributeStatement/saml:Attribute and //saml:Subject/saml:NameID, which select the first matching element in document order rather than the element covered by the verified signature. handle_response confirms that a signature is present and, when a cacert is configured, that it chains to the CA, but XML::Sig verifies only the element named by the signature's Reference URI, so unsigned sibling assertions in the same document are not covered. An attacker who holds any one IdP-signed assertion can add an unsigned attacker-authored assertion earlier in document order; the signature still verifies and the document-order XPath returns the attacker's NameID and attributes.

Any caller that passes an untrusted Response to newfromxml can accept identity fields from an assertion the IdP never signed, even when a cacert trust anchor is configured, so a party holding one valid IdP-signed assertion can authenticate as an arbitrary user.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "0.86"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "0.86"
                }
            ],
            "source": "DESCRIPTION"
        }
    ],
    "cna_assigner": "CPANSec",
    "cwe_ids": [
        "CWE-347"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18092.json"
}
References

Affected packages

Git / github.com/perl-net-saml2/perl-net-saml2

Affected ranges

Type
GIT
Repo
https://github.com/perl-net-saml2/perl-net-saml2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

0.*
0.19.05
0.20
0.20.03-TRIAL
0.25
0.29
0.30-TRIAL
0.31-TRIAL
0.32
0.33-TRIAL
0.34
0.35-TRIAL
0.36-TRIAL
0.37-TRIAL
0.38
0.39
0.40
0.41
0.42
0.43
0.44
0.45
0.47
0.48
0.49
0.51
0.52
0.53
0.54
0.55
0.56
0.57
0.58
0.60
0.61
0.62
0.63
0.64
0.65
0.66
0.67
0.68
0.69
0.70
0.71
0.72
0.73
0.74
0.75
0.76
0.77
0.78
0.79
0.80
0.81
0.82
0.83
0.84
0.85
perl-net-saml2-0.*
perl-net-saml2-0.19.05
v0.*
v0.10
v0.11
v0.12
v0.14
v0.15
v0.16
v0.17
v0.17_06
v0.20
v0.26-TRIAL

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18092.json"