Authentication Bypass in Net::SAML2 for Perl
CVE-2026-18108

Currently unrated

Key Information:

Vendor

Timlegge

Vendor
CVE Published:
3 August 2026

What is CVE-2026-18108?

The Net::SAML2 library for Perl prior to version 0.86 is vulnerable to an authentication bypass issue. This flaw arises because the method _verify_encrypted_assertion is able to accept an EncryptedAssertion whose decrypted content lacks a signature. Consequently, the method can erroneously return verified assertions without validating their authenticity. This means that any unauthorized party can decrypt and send an unsigned assertion to various services, potentially allowing them to authenticate as any user. Callers utilizing a decryption key_file are specifically at risk, as they may inadvertently accept unverified identity claims, while those without a key_file configuration remain unaffected.

Affected Version(s)

Net::SAML2 0 < 0.86

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.