CVE-2026-89042: passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification

Published Sep 10, 2026
·
Updated

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.

Affected Software

1 affected component
npm/passport-saml-encrypted<=0.1.13

Event History

Sep 10, 2026
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to authentication bypass?

Deployments using passport-saml-encrypted through version 0.1.13 are exposed when the SAML certificate option is not configured, because signature verification is then conditional rather than enforced.

2

What does an attacker need to exploit this issue?

An attacker can exploit the issue remotely without privileges or user interaction by submitting a forged, unsigned SAML response to the application's assertion consumer service endpoint. The forged response can contain an arbitrary NameID and attributes.

3

What is the effect of a successful exploit?

A successful attacker can receive an authenticated profile without providing a valid SAML signature. This can allow impersonation of identities represented by attacker-controlled NameID and attribute values.

4

What can be done while a package update is unavailable?

Configure the SAML certificate option so that signature verification is performed, and ensure the assertion consumer service endpoint does not accept unsigned SAML responses.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203