CRITICAL 9.1 CVE-2026-89042 Published 10 Sept 2026

Passport-SAML Unsigned Response Bypass

Worried this affects your website?

Passport-SAML, a SAML authentication library for Node.js, is vulnerable in versions up to 0.1.13.

Attackers can bypass authentication by submitting unsigned SAML responses to the assertion consumer service endpoint, allowing them to receive authenticated profiles with arbitrary NameID and attributes.

Reference: CVE-2026-89042 on NVD

← Back to Security News