Description
A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity from an unsigned assertion and authenticate the user without verifying a valid cryptographic signature.



As a result, an unauthenticated remote attacker may be able to submit a crafted SAML response and impersonate arbitrary users, including administrators
Published: 2026-09-16
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized user impersonation
Action: Patch Immediately
AI Analysis

Impact

A single vulnerability in the Kong SAML plugin allows an attacker to bypass authentication by supplying an unsigned SAML assertion when the validate_assertion_signature option is false, which is the default setting. Because the plugin trusts the assertion without verifying a cryptographic signature, an unauthenticated remote attacker can create a crafted SAML response that is treated as a valid login for any user, including an administrator. This flaw, a CWE-288 improper validation of cryptographic signature, directly affects the confidentiality and integrity of user identities and can lead to full system compromise.

Affected Systems

The affected component is Kong Enterprise Gateway’s SAML plugin. The plugin has the validate_assertion_signature option disabled by default, meaning the vulnerability applies to deployments that have not manually overridden this setting. Specific affected versions are not listed in the advisory, so all builds of Kong Enterprise Gateway containing the SAML plugin that rely on the default configuration are potentially vulnerable until a patch or configuration change is applied.

Risk and Exploitability

The CVSS score of 7.7 reflects a high severity due to the remote access, privilege escalation, and potential confidentiality and integrity impact. However, the EPSS score is below 1%, indicating that current exploit activity is very low. The vulnerability is not present in CISA’s KEV catalog. Attackers would need to send a crafted SAML assertion to a target Kong Gateway that accepts unsigned assertions, which is achievable over the network with reachable endpoints. If the gateway is exposed to the public internet and the default plugin configuration remains unchanged, an attacker could impersonate any user without authentication.

Generated by OpenCVE AI on September 18, 2026 at 10:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Set the validate_assertion_signature option to true in the Kong SAML plugin configuration to force signature validation on all assertions.
  • Apply the latest Kong Enterprise Gateway update that addresses the SAML authentication bypass, or upgrade to the latest version where the default configuration requires signed assertions.
  • Verify that all inbound SAML assertions are signed by a trusted identity provider and reject any unsigned assertions at the application or network layer.

Generated by OpenCVE AI on September 18, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Kong
Kong kong Enterprise Gateway
Vendors & Products Kong
Kong kong Enterprise Gateway

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Description A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity from an unsigned assertion and authenticate the user without verifying a valid cryptographic signature. As a result, an unauthenticated remote attacker may be able to submit a crafted SAML response and impersonate arbitrary users, including administrators
Title Kong API Gateway Enterprise: SAML Authentication bypass
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Kong Kong Enterprise Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: Kong

Published:

Updated: 2026-09-16T13:26:06.116Z

Reserved: 2026-07-07T07:14:57.290Z

Link: CVE-2026-14917

cve-icon Vulnrichment

Updated: 2026-09-16T13:26:01.470Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T10:16:48.373

Modified: 2026-09-18T19:07:38.320

Link: CVE-2026-14917

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:30:07Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel