(The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related fun ...) (CVE-2026-49283)
The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as cryptographically valid for the wrong identity provider. SOAPClient::addSSLValidator() attaches a TLS-based validator to the outer SOAP ArtifactResponse, while the embedded Response receives a validator that delegates to the outer message and is later checked against metadata selected from the embedded response issuer rather than necessarily the artifact issuer. SOAPClient::validateSSL() returns normally when the TLS public key does not match the key being validated, and SAML2\Message::validate() treats a validator call that does not throw as successful. In a multi-IdP federation, a malicious or lower-trust IdP can therefore provide an ArtifactResponse containing an unsigned Response that claims a higher-trust victim IdP as issuer and authenticate as arbitrary users with attacker-chosen assertion attributes, NameID, and session data. This issue is fixed in versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1.
AI Analysis
Technical Summary
The SimpleSAMLphp SAML2 library versions before 4.19.3, 4.20.2, 5.0.6, and 6.2.1 contain a vulnerability in the HTTPArtifact::receive() process. The vulnerability arises because the embedded SAML Response is validated against metadata from the embedded response issuer rather than the artifact issuer, combined with a TLS validator that does not properly enforce public key matching. Consequently, in multi-IdP federations, a malicious or lower-trust IdP can craft an ArtifactResponse with an unsigned Response claiming a higher-trust IdP as issuer, allowing authentication as arbitrary users with attacker-chosen assertion attributes, NameID, and session data. This improper certificate validation corresponds to CWE-295. The vulnerability is addressed in the fixed versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1.
Potential Impact
Successful exploitation allows a malicious or lower-trust identity provider in a multi-IdP federation to impersonate a higher-trust identity provider by providing an unsigned SAML Response that is treated as valid. This can lead to unauthorized authentication as arbitrary users with attacker-controlled attributes, potentially compromising confidentiality and integrity of authentication and session data. The CVSS v3.1 score is 8.7 (High), reflecting network attack vector, low complexity, high privileges required, no user interaction, scope change, and high impact on confidentiality and integrity.
Mitigation Recommendations
This vulnerability is fixed in SimpleSAMLphp SAML2 library versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1. Users should upgrade to one of these versions or later to remediate the issue. No other mitigations are indicated by the vendor advisory. Patch status is confirmed by the vendor advisory.
(The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related fun ...) (CVE-2026-49283)
Description
The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as cryptographically valid for the wrong identity provider. SOAPClient::addSSLValidator() attaches a TLS-based validator to the outer SOAP ArtifactResponse, while the embedded Response receives a validator that delegates to the outer message and is later checked against metadata selected from the embedded response issuer rather than necessarily the artifact issuer. SOAPClient::validateSSL() returns normally when the TLS public key does not match the key being validated, and SAML2\Message::validate() treats a validator call that does not throw as successful. In a multi-IdP federation, a malicious or lower-trust IdP can therefore provide an ArtifactResponse containing an unsigned Response that claims a higher-trust victim IdP as issuer and authenticate as arbitrary users with attacker-chosen assertion attributes, NameID, and session data. This issue is fixed in versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1.
CVSS v3.1
Score 8.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The SimpleSAMLphp SAML2 library versions before 4.19.3, 4.20.2, 5.0.6, and 6.2.1 contain a vulnerability in the HTTPArtifact::receive() process. The vulnerability arises because the embedded SAML Response is validated against metadata from the embedded response issuer rather than the artifact issuer, combined with a TLS validator that does not properly enforce public key matching. Consequently, in multi-IdP federations, a malicious or lower-trust IdP can craft an ArtifactResponse with an unsigned Response claiming a higher-trust IdP as issuer, allowing authentication as arbitrary users with attacker-chosen assertion attributes, NameID, and session data. This improper certificate validation corresponds to CWE-295. The vulnerability is addressed in the fixed versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1.
Potential Impact
Successful exploitation allows a malicious or lower-trust identity provider in a multi-IdP federation to impersonate a higher-trust identity provider by providing an unsigned SAML Response that is treated as valid. This can lead to unauthorized authentication as arbitrary users with attacker-controlled attributes, potentially compromising confidentiality and integrity of authentication and session data. The CVSS v3.1 score is 8.7 (High), reflecting network attack vector, low complexity, high privileges required, no user interaction, scope change, and high impact on confidentiality and integrity.
Mitigation Recommendations
This vulnerability is fixed in SimpleSAMLphp SAML2 library versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1. Users should upgrade to one of these versions or later to remediate the issue. No other mitigations are indicated by the vendor advisory. Patch status is confirmed by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-6929-8p9f-26jx
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-49283"]
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a46ecb227e9c7971943c58f
Added to database: 07/02/2026, 22:56:50 UTC
Last enriched: 08/20/2026, 11:16:59 UTC
Last updated: 09/12/2026, 22:01:34 UTC
Views: 119
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.