CVE-2026-86304 is a critical (CVSS 3.1 base 9.8) SAML authentication-bypass vulnerability in MojoX::Authentication, versions before 0.006, a CPAN module providing SAML2-based login for Mojolicious Perl applications.
What the vulnerability does
Per NVD’s description, the module’s parse_assertion function (in MojoX::Authentication::Model::SAML2) constructs a Net::SAML2::Binding::POST object without supplying a trust anchor — no CA certificate, certificate text, or anchor list. It then passes the resulting XML to Net::SAML2::Protocol::Assertion->new_from_xml, supplying the identity provider’s signing certificate as the cacert parameter. In Net::SAML2 versions before 0.86, that certificate only guards encrypted assertions — meaning the signature on an unencrypted assertion is checked against whatever certificate the SAML response itself carries, not the identity provider’s real certificate.
The exploit path: an attacker starts a SAML login flow, then submits a response signed with a certificate they control themselves. Since the signature check validates against the attacker’s own embedded certificate rather than the real IdP certificate, and the remaining checks (audience, InResponseTo, timestamp) are all satisfiable by an attacker crafting their own response, the forged assertion authenticates as any NameID the attacker chooses to include.
The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects a network-reachable, low-complexity flaw needing no authentication or user interaction, with full confidentiality, integrity, and availability impact — consistent with an attacker being able to authenticate as any user, including administrators.
Fix and affected versions
Fixed in MojoX::Authentication 0.006 and later, per NVD’s reference to the module’s changelog. Applications should also confirm they’re running Net::SAML2 0.86 or later, since the underlying trust-anchor enforcement gap lives in that dependency.
What we don’t yet have
This record traces to NVD and the module’s own upstream metacpan/changelog references — no independent second-source corroboration or CISA KEV listing is present, so confidence is medium.
Why this matters
SAML SSO is typically deployed specifically to centralize and harden authentication — a bypass that lets an attacker forge their own signing certificate defeats that purpose entirely, since it means the application’s SAML integration was never actually verifying assertions came from the real identity provider. Any Mojolicious application using this module for SSO should treat this as a full authentication-bypass emergency, not a routine dependency update.
Frequently Asked Questions
What is CVE-2026-86304?
A CVSS 9.8 critical SAML authentication-bypass vulnerability in the Perl MojoX::Authentication module, allowing an attacker to forge a self-signed SAML response and authenticate as any user.
Which version fixes CVE-2026-86304?
MojoX::Authentication 0.006 and later; also confirm Net::SAML2 0.86 or later.
Is CVE-2026-86304 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.
Data sourced from the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.