Authentication Bypass Vulnerability in passport-saml-encrypted Product by KrakenJS
CVE-2026-89042
9.3CRITICAL
What is CVE-2026-89042?
The passport-saml-encrypted package, up to version 0.1.13, is susceptible to an authentication bypass due to its reliance on an optional certificate option for SAML signature verification. This flaw permits attackers to send forged SAML responses devoid of valid signatures, potentially gaining unauthorized access. By targeting the assertion consumer service endpoint, adversaries can exploit this weakness to manipulate NameID and attributes, compromising the integrity of user authentication.
Affected Version(s)
passport-saml-encrypted 0 <= 0.1.13
