www.vulncheck.com Critical XML Signature Wrapping Vulnerability in passport-saml-encrypted
Article Content
- •CVE-2026-89043 affects passport-saml-encrypted version 0.1.13.
- •Attackers can exploit this flaw to impersonate identities without the signing key.
- •Immediate upgrade to a fixed version is necessary to mitigate risks.
The passport-saml-encrypted library version 0.1.13 contains a critical XML signature wrapping vulnerability, identified as CVE-2026-89043, allowing attackers to prepend forged unsigned assertions to validly signed SAML messages. This flaw enables identity impersonation, potentially leading to account takeovers and unauthorized access to sensitive applications. The vulnerability arises from independent XPath lookups for signature verification and assertion extraction, which lack cross-validation. Organizations using this library, particularly in internet-facing Node.js applications, are at high risk. Public proof-of-concept evidence has been released, increasing concerns about potential exploitation, although active exploitation has not yet been confirmed. Immediate action is recommended to mitigate risks associated with this vulnerability.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2017-11429 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…