Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

New CVE Detected

CVE-2026-89042 – Authentication Bypass via Missing Signature Verification – passport-saml-encrypted

Be the first to know when new zero-days emerge:

Summary

CVE-2026-89042 is a critical authentication bypass vulnerability in passport-saml-encrypted, an npm package (maintained under the krakenjs organization) that implements a Passport.js strategy for SAML authentication with support for encrypted assertions. The library makes SAML response signature verification conditional on the optional cert configuration option, meaning that if an implementer does not explicitly configure a certificate, signature checks are silently skipped and unsigned, attacker-forged SAML responses are accepted as valid. The issue carries a CVSS score of 9.3 (Critical) and can lead to full authentication bypass and account impersonation.

Technical details

  • Root cause: In lib/saml.js, SAML.prototype.validateResponse() gates signature validation behind a truthy check on self.options.cert (e.g. if (self.options.cert && !self.validateSignature(...))). When cert is not set, the entire signature-verification branch is bypassed rather than failing closed.
  • Trigger conditions: The vulnerable code path is reached whenever an application integrates passport-saml-encrypted without explicitly supplying the cert option — a configuration gap made more likely because the project’s own README example omits cert entirely.
  • Attack vector: Network-based, no authentication or user interaction required. An attacker crafts an unsigned SAML response with forged claims (e.g., an arbitrary NameID such as a victim’s email, or elevated role/attribute values) and POSTs it directly to the application’s Assertion Consumer Service (ACS) endpoint.
  • Impact: Because the response is never cryptographically validated, the application accepts the forged identity and claims as authentic, allowing an attacker to impersonate any user — including privileged accounts — resulting in full authentication bypass with high confidentiality and integrity impact.

Affected software

  • passport-saml-encrypted (npm package, krakenjs/passport-saml-encrypted) — all versions through 0.1.13

Severity

  • CVSS v3.1 Base Score: 9.1 (Critical) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • CVSS v4.0 Score: 9.3 (Critical) — CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  • CWE-347: Improper Verification of Cryptographic Signature

Mitigation and recommended actions

  • Immediate: As of the latest available information, no patched release of passport-saml-encrypted has been published to resolve this issue; the upstream GitHub issue remains open with no merged fix. Security teams should treat any deployment of this package as vulnerable regardless of version.
  • Workarounds / network mitigations:
    • Explicitly configure the cert option with the Identity Provider’s signing certificate for every instance of passport-saml-encrypted in use, and verify (via code review or testing) that unsigned SAML responses are rejected.
    • Where feasible, migrate away from passport-saml-encrypted to an actively maintained SAML library that enforces signature verification unconditionally (fail-closed by default).
    • Add application-layer checks that explicitly reject any SAML response lacking a valid <Signature> element before it reaches the library’s validation logic.
    • Monitor SSO/ACS endpoints for anomalous unsigned SAML POST requests as an interim detection measure.
    • Enforce additional identity assurance controls (e.g., step-up authentication, session anomaly detection) for SSO-authenticated sessions until the library is remediated or replaced.

References

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

How IONIX’s External Exposure Management Platform Detects and Validates
Zero-Days to Shrink MTTR

1

Map your entire attack surface (continously)

IONIX uses multi-factor discovery methods, including DNS analysis, certificate mapping, metadata inspection, and more, to automatically map every internet-facing asset across your environment. This includes cloud instances, third-party platforms, shadow IT, and even forgotten infrastructure that traditional tools miss.

2

Monitor for new CVEs

Dozens of threat intel feeds using agentic technology are continuously analyzed to detect the appearance of proof-of-concept code, exploit kits, and indicators of active targeting. IONIX goes further by applying AI to proactively evaluate whether emerging vulnerabilities are likely to be exploited, even before PoCs go public.

3

Identify Potential External Exposures

Not all CVEs matter. IONIX filters vulnerabilities by asking attacker-centric questions: Can it be reached from the internet? Does it require authentication? Is it being exploited in the wild? This dramatically reduces noise and focuses teams on threats that can actually be weaponized.

4

Create Safe, Scalable Exploit Validations

IONIX transforms real-world PoCs into safe, non-intrusive test payloads that can be run in production environments without disruption. These simulations are precisely targeted to the systems that are vulnerable, ensuring rapid validation without unnecessary load.

5

Execute Exploit Validations

By combining context about software stack, versioning, exposure status, and reachability, IONIX ensures that only the right payloads are executed against the right assets, maximizing efficiency and minimizing risk.

6

Drive Fast and Actionable Remediation

Results are routed through integrations with ticketing, SOAR, and SIEM tools. Issues are written in plain language, bundled into remediation clusters, and prioritized based on asset criticality, exploitability, and blast radius. This shortens mean time to remediation (MTTR) and empowers teams to act with confidence.

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge