SAML2 Library Vulnerability in SimpleSAMLphp Affects Multiple Identity Providers
CVE-2026-49283

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-49283?

The SimpleSAMLphp SAML2 library features a vulnerability that allows an unsigned SAML Response embedded within an ArtifactResponse to be treated as valid by a higher-trust identity provider in a multi-IdP context. This issue arises because the HTTPArtifact::receive() function may allow a malicious or lower-trust IdP to generate a response that incorrectly authenticates users with attacker-chosen attributes and session data. The flaw stems from inadequate checks within the SOAPClient's SSL validation mechanisms. It has been addressed in versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1.

Affected Version(s)

saml2 < 4.19.3 < 4.19.3

saml2 >= 4.20.0, < 4.20.2 < 4.20.0, 4.20.2

saml2 >= 5.0.0, < 5.0.6 < 5.0.0, 5.0.6

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.