Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-18092— Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree

Quick assessment

Affected
TIMLEGGE Net::SAML2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

timlegge Net::SAML2是timlegge个人开发者的一款实现SAML2协议的Perl库。 TIMLEGGE Net::SAML2 0.86之前版本存在加密问题漏洞,该漏洞源于new_from_xml读取断言身份时使用文档范围的XPath而非签名子树,可能导致SAML身份验证绕过,攻击者持有一个IdP签名的断言即可添加未签名的攻击者断言,从而以任意用户身份进行认证。

AI Predicted 9.8 Difficulty: Easy EPSS 0.34% · P25

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
TIMLEGGE Net::SAML2 < 0.86 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18092

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree
Source: CVE Program / CVE List V5
Vulnerability Description
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree. new_from_xml reads the NameID, attribute values, SessionIndex, audience and other identity fields with document-wide XPath, such as //saml:Assertion/saml:AttributeStatement/saml:Attribute and //saml:Subject/saml:NameID, which select the first matching element in document order rather than the element covered by the verified signature. handle_response confirms that a signature is present and, when a cacert is configured, that it chains to the CA, but XML::Sig verifies only the element named by the signature's Reference URI, so unsigned sibling assertions in the same document are not covered. An attacker who holds any one IdP-signed assertion can add an unsigned attacker-authored assertion earlier in document order; the signature still verifies and the document-order XPath returns the attacker's NameID and attributes. Any caller that passes an untrusted Response to new_from_xml can accept identity fields from an assertion the IdP never signed, even when a cacert trust anchor is configured, so a party holding one valid IdP-signed assertion can authenticate as an arbitrary user.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
密码学签名的验证不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
TIMLEGGE Net::SAML2 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
timlegge Net::SAML2是timlegge个人开发者的一款实现SAML2协议的Perl库。 TIMLEGGE Net::SAML2 0.86之前版本存在加密问题漏洞,该漏洞源于new_from_xml读取断言身份时使用文档范围的XPath而非签名子树,可能导致SAML身份验证绕过,攻击者持有一个IdP签名的断言即可添加未签名的攻击者断言,从而以任意用户身份进行认证。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
TIMLEGGE Net::SAML2 0 ~ 0.86 -

II. Public POCs for CVE-2026-18092

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18092

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-18092 (1)

Other References for CVE-2026-18092 (1)

Same Patch Batch · TIMLEGGE · 2026-08-03 · 6 CVEs total

CVE-2026-18108 Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encry
CVE-2026-18089 Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying res
CVE-2026-9390 XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup
CVE-2026-9487 XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID
CVE-2026-18568 XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass becau

IV. Related Vulnerabilities

V. Comments for CVE-2026-18092

No comments yet


Leave a comment