Review
POLETTIX
CVE published 2026-09-06
CVE-2026-86304
CVE-2026-86304 is a SAML authentication bypass vulnerability in MojoX::Authentication versions before 0.006 for Perl. The vulnerability arises from the `parse_assertion` function in MojoX::Authentication::Model::SAML2, which constructs a Net::SAML2::Binding::POST object without a trust anchor, allowing an attacker to post a response signed with their own certificate, thereby bypassing authentication.