---
cve: "CVE-2026-86304"
severity: "LOW"
cvss: 3.1
epss: "3.1%"
vendor: "Generic Security"
kev: false
exploited: false
published: "2026-09-06 23:17:39"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-07T07:04:56+02:00"
---

# CVE-2026-86304

> 3.1 LOW

## Beschreibung

MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor.

parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no cacert, cert_text or anchors argument, then passes the returned XML to Net::SAML2::Protocol::Assertion->new_from_xml with the IdP signing certificate as cacert. In Net::SAML2 before 0.86 that certificate guards only encrypted assertions, so the signature on an unencrypted assertion is checked against the certificate the response itself carries.

An attacker starts a SAML login, then posts a response signed with a certificate of their own. The audience, InResponseTo and timestamp checks that follow are all satisfiable by the attacker, so the response authenticates any NameID it carries.

## Referenzen

- <https://metacpan.org/release/POLETTIX/MojoX-Authentication-0.004/source/lib/MojoX/Authentication/Model/SAML2.pm#L188>
- <https://metacpan.org/release/POLETTIX/MojoX-Authentication-0.006/source/Changes>
- <https://www.cve.org/CVERecord?id=CVE-2026-18089>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-86304) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
