Skip to main content
QUIETLYTIC
Vulnerability

MojoX::Authentication Authentication Bypass (CVE-2026-86304)

CVE-2026-86304 is a CVSS 9.8 critical SAML authentication bypass in the Perl MojoX::Authentication module, letting an attacker forge a self-signed SAML response to log in as any user.

CVE-2026-86304
Threat Level
CRITICAL
CVSS
9.8
Status
Monitored
Confidence
Medium
Affected Products
MojoX::Authentication (CPAN)

CVE-2026-86304 is a critical (CVSS 3.1 base 9.8) SAML authentication-bypass vulnerability in MojoX::Authentication, versions before 0.006, a CPAN module providing SAML2-based login for Mojolicious Perl applications.

What the vulnerability does

Per NVD’s description, the module’s parse_assertion function (in MojoX::Authentication::Model::SAML2) constructs a Net::SAML2::Binding::POST object without supplying a trust anchor — no CA certificate, certificate text, or anchor list. It then passes the resulting XML to Net::SAML2::Protocol::Assertion->new_from_xml, supplying the identity provider’s signing certificate as the cacert parameter. In Net::SAML2 versions before 0.86, that certificate only guards encrypted assertions — meaning the signature on an unencrypted assertion is checked against whatever certificate the SAML response itself carries, not the identity provider’s real certificate.

The exploit path: an attacker starts a SAML login flow, then submits a response signed with a certificate they control themselves. Since the signature check validates against the attacker’s own embedded certificate rather than the real IdP certificate, and the remaining checks (audience, InResponseTo, timestamp) are all satisfiable by an attacker crafting their own response, the forged assertion authenticates as any NameID the attacker chooses to include.

The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects a network-reachable, low-complexity flaw needing no authentication or user interaction, with full confidentiality, integrity, and availability impact — consistent with an attacker being able to authenticate as any user, including administrators.

Fix and affected versions

Fixed in MojoX::Authentication 0.006 and later, per NVD’s reference to the module’s changelog. Applications should also confirm they’re running Net::SAML2 0.86 or later, since the underlying trust-anchor enforcement gap lives in that dependency.

What we don’t yet have

This record traces to NVD and the module’s own upstream metacpan/changelog references — no independent second-source corroboration or CISA KEV listing is present, so confidence is medium.

Why this matters

SAML SSO is typically deployed specifically to centralize and harden authentication — a bypass that lets an attacker forge their own signing certificate defeats that purpose entirely, since it means the application’s SAML integration was never actually verifying assertions came from the real identity provider. Any Mojolicious application using this module for SSO should treat this as a full authentication-bypass emergency, not a routine dependency update.

Frequently Asked Questions

What is CVE-2026-86304? A CVSS 9.8 critical SAML authentication-bypass vulnerability in the Perl MojoX::Authentication module, allowing an attacker to forge a self-signed SAML response and authenticate as any user.

Which version fixes CVE-2026-86304? MojoX::Authentication 0.006 and later; also confirm Net::SAML2 0.86 or later.

Is CVE-2026-86304 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.


Data sourced from the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)

Related intelligence


Analyst tools