CVE-2026-31982: Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0
An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can craft a request to the SAML sign-in endpoint and poison the cached SAML redirection for other users who subsequently initiate SAML Single Sign-On, enabling phishing and credential-theft attacks, as well as disrupting SAML authentication for all affected users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Guardian/CMCto a version that resolves this vulnerability.Fixed in 26.2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31982?
The severity of CVE-2026-31982 is rated as medium with a score of 5.3.
How do I fix CVE-2026-31982?
To fix CVE-2026-31982, update to Guardian/CMC version 26.2.0 or later.
What kind of vulnerability is CVE-2026-31982?
CVE-2026-31982 is an Open Redirect vulnerability in the SAML Single Sign-On functionality.
Who is affected by CVE-2026-31982?
Users of Guardian/CMC SAML Single Sign-On prior to version 26.2.0 are affected by CVE-2026-31982.
What can an attacker do with CVE-2026-31982?
An attacker can exploit CVE-2026-31982 to poison the cached SAML redirection, potentially redirecting other users to malicious sites.