Known Vulnerabilities for Saml by Saml Project
Listed below are 4 of the newest known vulnerabilities associated with "Saml" by "Saml Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-94613 json | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can sub... | Not Provided | 2026-09-24 | 2026-09-29 |
| CVE-2026-94612 json | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies a... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2026-94212 json | Improper verification of cryptographic signature vulnerability in Apache APISIX. Any unauthenticated attacker could impers... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-89043 json | passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and asse... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-89042 json | passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing att... | Not Provided | 2026-09-10 | 2026-09-11 |
| CVE-2026-88920 json | An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authe... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-86770 json | Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authentic... | Not Provided | 2026-09-09 | 2026-09-14 |
| CVE-2026-86756 json | Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController:... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-86597 json | Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allow... | Not Provided | 2026-09-08 | 2026-09-10 |
| CVE-2026-86304 json | MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAM... | Not Provided | 2026-09-06 | 2026-09-08 |