PatchSiren

krakenjs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL krakenjs CVE published 2026-09-10

CVE-2026-89042

CVE-2026-89042 is a critical vulnerability in the passport-saml-encrypted package, which allows attackers to bypass authentication by submitting unsigned SAML responses. The vulnerability has a CVSS score of 9.3 and is considered critical. The CVE record was published on 2026-09-10T18:18:15.910Z and was last modified on 2026-09-11T21:17:56.573Z. The NVD entry is currently Deferred.