Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2026-53425

PUBLISHED 21.08.2026

CNA: EEF

Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses

Обновлено: 20.08.2026
Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested. Samly.SPHandler.validate_authresp/3 in lib/samly/sp_handler.ex validates a SAML response for the SP-initiated flow by comparing only the RelayState value, the IdP identifier, and the presence of a target URL held in the session. It never compares SubjectConfirmationData/@InResponseTo against the ID of the AuthnRequest the service provider issued, and that request ID is never persisted, so no comparison is possible. SAML 2.0 Core section 4.1.4.3 requires a service provider to reject a response whose InResponseTo does not match a request it made. The underlying esaml library checks status, signature, recipient, audience, and staleness, but likewise never inspects InResponseTo, so nothing else closes the gap. Exploitation requires a validly signed assertion from the trusted IdP, which an attacker can obtain for their own account, and a RelayState matching the victim's session; the assertion signature itself remains intact, so this is not a signature-forgery issue. This issue affects samly: from 0.3.0 onward.

CWE

Идентификатор Описание
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

CVSS

Оценка Severity Версия Базовый вектор
7.6 HIGH 4.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

EPSS

Вероятность Severity Процентиль ? Дата расчёта
0.18% LOW 7.39 30.08.2026

Доп. Информация

Product Status

samly
Product: samly
Vendor: dropbox
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0.3.0 до * affected
СPE:
  • cpe:2.3:a:dropbox:samly:*:*:*:*:*:*:*:*
samly
Product: samly
Vendor: dropbox
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 8a5bb1b4a4753d05470da2036323477f63cfdf4c до * affected
СPE:
  • cpe:2.3:a:dropbox:samly:*:*:*:*:*:*:*:*
samly
Product: samly
Vendor: handnot2
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 8a5bb1b4a4753d05470da2036323477f63cfdf4c до * affected
СPE:
  • cpe:2.3:a:handnot2:samly:*:*:*:*:*:*:*:*
 

Ссылки

CISA ADP Vulnrichment

Обновлено: 21.08.2026
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
none no total 2.0.3 21.08.2026

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.