PatchSiren

POLETTIX CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review POLETTIX CVE published 2026-09-06

CVE-2026-86304

CVE-2026-86304 is a SAML authentication bypass vulnerability in MojoX::Authentication versions before 0.006 for Perl. The vulnerability arises from the `parse_assertion` function in MojoX::Authentication::Model::SAML2, which constructs a Net::SAML2::Binding::POST object without a trust anchor, allowing an attacker to post a response signed with their own certificate, thereby bypassing authentication.