PT-2026-67414 · Lightsaml+1 · Lightsaml+1

·

CVE-2026-69092

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Admidio versions prior to 5.0.11
Description A reflected cross-site scripting issue exists in the SSO/SAML endpoint. The system echoes unencoded exception messages in the HTTP response, allowing unauthenticated attackers to inject arbitrary JavaScript. This can be achieved through SAML Issuer elements or LightSaml library parameters, potentially leading to code execution in users' browsers and session hijacking.
Recommendations Update to version 5.0.11 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-69092
GHSA-7JXV-38F3-6XGF

Affected Products

Admidio
Lightsaml