PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14917 Kong CVE debrief

A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity from an unsigned assertion and authenticate the user without verifying a valid cryptographic signature. As a result, an unauthenticated remote attacker may be able to submit a crafted SAML response and impersonate arbitrary users, including administrators.

Vendor
Kong
Product
Kong Enterprise Gateway
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-18
Advisory published
2026-09-16
Advisory updated
2026-09-18

Who should care

Defenders responsible for configuring and maintaining the Kong SAML plugin should verify the validate_assertion_signature option and ensure it is not set to false. They should also consider upgrading to a version of the plugin that fixes the vulnerability, if available, and monitor for suspicious SAML authentication attempts.

Why it matters

Defenders should prioritize verifying the validate_assertion_signature option and ensuring it is not set to false in their Kong SAML plugin configurations to prevent authentication bypass.

  • An unauthenticated remote attacker may be able to impersonate arbitrary users, including administrators.
  • The vulnerability allows for authentication bypass, potentially leading to unauthorized access.

Technical summary

The Kong SAML plugin has a vulnerability that allows an unauthenticated remote attacker to bypass SAML authentication when the validate_assertion_signature option is set to false. This option is enabled by default. An attacker can submit a crafted SAML response to impersonate arbitrary users, including administrators. The vulnerability affects the Kong SAML plugin and defenders should prioritize verifying the validate_assertion_signature option and ensuring it is not set to false in their Kong SAML plugin configurations.

Defensive priority

Defenders should prioritize verifying the validate_assertion_signature option and ensuring it is not set to false in their Kong SAML plugin configurations.

Recommended defensive actions

  • Verify the validate_assertion_signature option in Kong SAML plugin configurations and ensure it is not set to false.
  • Consider upgrading to a version of the Kong SAML plugin that fixes the vulnerability, if available.
  • Monitor for suspicious SAML authentication attempts.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD vulnerability detail page provide information about the vulnerability, but do not specify which versions of the Kong SAML plugin are affected or provide a patch. Defenders should verify the validate_assertion_signature option and ensure it is not set to false in their Kong SAML plugin configurations. The vulnerability allows for authentication bypass, potentially leading to unauthorized access. Evidence is limited to CVE and NVD details.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-14917 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-14917

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-14917 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14917

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://developer.konghq.com/gateway/changelog/

    02762ae7-200e-4b20-9b2b-a77d5b8fc4cb

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.