Description
passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SAML message can prepend a forged unsigned assertion that gets accepted as the verified identity while the genuine signature validates against the original assertion.
Published: 2026-09-10
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Patch Now
AI Analysis

Impact

This vulnerability allows an attacker who possesses any validly signed SAML message to prepend an unsigned assertion to the message. The library processes signature verification and assertion extraction using separate XPath lookups without cross‑validation. As a result, the forged assertion is accepted as the authenticated identity while the original signature is validated against the original assertion, enabling the attacker to impersonate arbitrary users.

Affected Systems

The issue is present in the krakenjs passport-saml-encrypted package. All versions up to and including 0.1.13 are impacted.

Risk and Exploitability

The CVSS score of 9.1 classifies this condition as critical. Although an EPSS score is not available, the lack of a KE wild yet; however, the high intrinsic severity and the ability to bypass authentication give attackers a severe advantage when they can supply a signed SAML payload. The vulnerability is exploitable remotely through any system that accepts SAML responses processed by the affected library. Attackers with the ability to supply or manipulate SAML assertions can gain unauthorized access or elevate privileges.

Generated by OpenCVE AI on September 11, 2026 at 00:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the passport‑saml‑encrypted package to a patched version if available.
  • Enforce strict signature validation logic that verifies the signing path of the assertion before extracting user information.
  • Reject unsigned SAML assertions at the application level until the library is upgraded.

Generated by OpenCVE AI on September 11, 2026 at 00:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Krakenjs
Krakenjs passport-saml-encrypted
Vendors & Products Krakenjs
Krakenjs passport-saml-encrypted

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SAML message can prepend a forged unsigned assertion that gets accepted as the verified identity while the genuine signature validates against the original assertion.
Title passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Krakenjs Passport-saml-encrypted
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T17:53:56.984Z

Reserved: 2026-09-10T16:45:09.299Z

Link: CVE-2026-89043

cve-icon Vulnrichment

Updated: 2026-09-10T17:53:52.098Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T18:18:16.073

Modified: 2026-09-10T19:58:20.507

Link: CVE-2026-89043

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:00:01Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature