CRITICAL
9.1 CVE-2026-89042 Published 10 Sept 2026
Passport-SAML Unsigned Response Bypass
Worried this affects your website?
Passport-SAML, a SAML authentication library for Node.js, is vulnerable in versions up to 0.1.13.
Attackers can bypass authentication by submitting unsigned SAML responses to the assertion consumer service endpoint, allowing them to receive authenticated profiles with arbitrary NameID and attributes.
Reference: CVE-2026-89042 on NVD
← Back to Security News