CVE-2026-86304 PUBLISHED

MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor

Assigner: CPANSec
Reserved: 06.09.2026 Published: 06.09.2026 Updated: 06.09.2026

MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor.

parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no cacert, cert_text or anchors argument, then passes the returned XML to Net::SAML2::Protocol::Assertion->new_from_xml with the IdP signing certificate as cacert. In Net::SAML2 before 0.86 that certificate guards only encrypted assertions, so the signature on an unencrypted assertion is checked against the certificate the response itself carries.

An attacker starts a SAML login, then posts a response signed with a certificate of their own. The audience, InResponseTo and timestamp checks that follow are all satisfiable by the attacker, so the response authenticates any NameID it carries.

Product Status

Package Collection https://cpan.org/modules
Package Name MojoX-Authentication
Versions Default: unaffected
  • affected from 0 to 0.006 (excl.)

Workarounds

For deployments that cannot upgrade, install Net::SAML2 0.86 or later. SAML login then fails rather than accepting a forged assertion.

Solutions

Upgrade to MojoX-Authentication 0.006 or later.

References

Problem Types

  • CWE-347 Improper Verification of Cryptographic Signature CWE

Impacts

  • CAPEC-115 Authentication Bypass