CVE-2026-41694: SAML Payloads Decrypted Without Valid Signature
Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle.
Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41694?
The severity of CVE-2026-41694 is classified as medium with a score of 5.3.
What vulnerabilities does CVE-2026-41694 present?
CVE-2026-41694 allows attackers to exploit SAML payloads that are decrypted without a valid signature, potentially leading to unauthorized access.
How does CVE-2026-41694 affect Spring Security?
CVE-2026-41694 affects Spring Security versions 5.7.0 through affected versions by allowing decryption of SAML Responses and Logout payloads without signature validation.
How can I mitigate the risks associated with CVE-2026-41694?
To mitigate CVE-2026-41694, update to the latest version of Spring Security that addresses this vulnerability.
What software is affected by CVE-2026-41694?
CVE-2026-41694 affects VMware Spring Security, specifically the SAML2 service provider component.