What is CVE-2026-18089?
CVE-2026-18089 is a SAML authentication bypass vulnerability in Net::SAML2 for Perl prior to version 0.86. The verify_xml function verifies responses against the response-embedded certificate when no trust anchor is configured, allowing attackers to bypass authentication. Users should upgrade to Net::SAML2 version 0.86 or later.
Azərbaycanca: CVE-2026-18089, Perl üçün Net::SAML2 kitabxanasının 0.86-dan əvvəlki versiyalarında SAML autentifikasiya bypass zəifliyidir. verify_xml funksiyası etibarlı lövbər (trust anchor) konfiqurasiya edilmədikdə cavabda olan sertifikata qarşı yoxlama apararaq autentifikasiyanı yan keçməyə imkan verir. Təsirə məruz qalan sistemlərdə Net::SAML2 kitabxanasını ən azı 0.86 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of the Net::SAML2 library are affected by CVE-2026-18089?
This vulnerability exists in Net::SAML2 for Perl prior to version 0.86.
What is the root cause of the authentication bypass vulnerability in CVE-2026-18089?
The vulnerability occurs because the verify_xml function verifies against the certificate embedded in the response when no trust anchor is configured.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.