PT-2026-79072 · Samly · Samly

·

CVE-2026-53424

·

Published

2026-08-20

·

Updated

2026-08-21

CVSS v4.0

9.1

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions dropbox samly versions 0.3.0 and later
Description An authentication bypass exists where an attacker can authenticate as the subject of a captured SAML assertion by resubmitting it. This occurs because the function decode idp auth resp/3 in lib/samly/helper.ex calls validate assertion/2, which uses a default duplicate detector that does not perform any action. Consequently, the SAML 2.0 Web Browser SSO Profile requirement to use a bearer assertion only once is not enforced. An attacker who obtains a valid SAMLResponse from network traffic, browser history, or logs can repeatedly submit the same data to establish sessions as the assertion's subject until the NotOnOrAfter timestamp expires.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53424

Affected Products

Samly