Authentication Bypass Vulnerability in passport-saml-encrypted Product by KrakenJS
CVE-2026-89042

9.3CRITICAL

Key Information:

Vendor

Krakenjs

Vendor
CVE Published:
10 September 2026

What is CVE-2026-89042?

The passport-saml-encrypted package, up to version 0.1.13, is susceptible to an authentication bypass due to its reliance on an optional certificate option for SAML signature verification. This flaw permits attackers to send forged SAML responses devoid of valid signatures, potentially gaining unauthorized access. By targeting the assertion consumer service endpoint, adversaries can exploit this weakness to manipulate NameID and attributes, compromising the integrity of user authentication.

Affected Version(s)

passport-saml-encrypted 0 <= 0.1.13

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yu Bao, PayPal Cyber Security Team
.