PT-2026-79073 · Samly · Samly

·

CVE-2026-53425

·

Published

2026-08-20

·

Updated

2026-08-21

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions dropbox samly versions 0.3.0 and later
Description An issue exists where the service provider fails to properly verify the authenticity of SAML responses. Specifically, the validate authresp/3 function in lib/samly/sp handler.ex does not compare the SubjectConfirmationData/@InResponseTo attribute against the ID of the AuthnRequest issued by the service provider. Because the request ID is not persisted, the system cannot verify if the response corresponds to a request it actually made, which violates SAML 2.0 Core requirements. An attacker with a validly signed assertion from a trusted Identity Provider (IdP) for their own account and a RelayState matching the victim's session can establish an authenticated session using a response the service provider never requested.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53425

Affected Products

Samly