Insufficient Verification of Data Authenticity in Dropbox Samly
CVE-2026-53425
What is CVE-2026-53425?
The vulnerability in Dropbox's Samly involves insufficient validation of SAML response authenticity. An attacker can exploit this issue by establishing an authenticated session using a SAML response that was never requested by the service provider. The affected function in Samly compares only a subset of data, neglecting crucial elements such as the comparison of InResponseTo against the respective AuthnRequest ID, which is not retained for validation. This gap allows attackers with access to a validly signed assertion from a trusted Identity Provider (IdP) to potentially hijack user sessions by matching the RelayState with the victim's session. The underlying security checks are bypassed due to this oversight, making it imperative for users to address this vulnerability.
Affected Version(s)
samly 0.3.0
samly 8a5bb1b4a4753d05470da2036323477f63cfdf4c
samly 8a5bb1b4a4753d05470da2036323477f63cfdf4c
