PT-2026-55453 · Simplesamlphp+4 · Simplesamlphp+1

CVE-2026-49284

·

Published

2026-07-02

·

Updated

2026-07-17

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions SimpleSAMLphp versions prior to 1.18.6 SimpleSAMLphp versions prior to 2.4.7 SimpleSAMLphp versions prior to 2.5.2
Description The SAML SP ACS path fails to enforce the Identity Provider (IdP) selected during an SP-initiated login. When a saved SP state expects a specific IdP, but the ACS receives a valid response from a different trusted IdP, the system logs a warning and continues processing instead of rejecting the response. This occurs when an unsigned samlp:Response/@InResponseTo is used in conjunction with a signed assertion that lacks SubjectConfirmationData/InResponseTo. Consequently, a response from one trusted IdP can be bound to an SP state created for another, allowing a lower-trust IdP to satisfy state created for a different expected IdP. This can lead to an authentication or authorization bypass in multi-IdP deployments, especially those where enable unsolicited is set to false to prevent IdP-initiated logins.
Recommendations Update to version 1.18.6 or later. Update to version 2.4.7 or later. Update to version 2.5.2 or later.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49284
GHSA-Q8R6-XJ3F-WRRM

Affected Products

Simplesamlphp
Simplesamlphp/Simplesamlphp