XML Signature Wrapping Vulnerability in KrakenJS Passport-SAML-Encryped
CVE-2026-89043

9.1CRITICAL

Key Information:

Vendor

Krakenjs

Vendor
CVE Published:
10 September 2026

What is CVE-2026-89043?

The passport-saml-encrypted package through version 0.1.13 is susceptible to an XML signature wrapping vulnerability. This issue arises due to the usage of independent XPath lookups for signature verification and assertion extraction without cross-validation. As a result, an attacker can prepend a forged unsigned assertion to a validly signed SAML message, leading it to be misinterpreted as a verified identity. This flaw can potentially allow unauthorized access and manipulation of user identities.

Affected Version(s)

passport-saml-encrypted 0 <= 0.1.13

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yu Bao, PayPal Cyber Security Team
.