What is CVE-2026-18092?
CVE-2026-18092 allows SAML authentication bypass via XML signature wrapping in Net::SAML2 for Perl versions before 0.86. The vulnerability arises because new_from_xml reads identity information using a document-wide XPath instead of the signed subtree. Upgrading to Net::SAML2 version 0.86 or later is required.
Azərbaycanca: CVE-2026-18092 Perl üçün Net::SAML2 modulunun 0.86-dan əvvəlki versiyalarında XML imza sarma hücumu vasitəsilə SAML autentifikasiyasından yan keçməyə imkan verir. XPath-in səhv tətbiqi səbəbindən istifadə olunan identiklik məlumatları imzalanmış alt-ağac əvəzinə bütün sənəd üzrə oxunur. Təcili olaraq Net::SAML2 modulunu 0.86 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
What is CVE-2026-18092 and which component does it affect?
CVE-2026-18092 is a vulnerability that allows SAML authentication bypass via XML signature wrapping in Net::SAML2 for Perl versions before 0.86. The issue arises because the new_from_xml function reads identity information using a document-wide XPath instead of the signed subtree.
How can CVE-2026-18092 be mitigated?
To mitigate this vulnerability, it is recommended to urgently upgrade the Net::SAML2 module to version 0.86 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.