SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-53424

CRITICAL · CVSS 9.1 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows attackers to bypass authentication in the Samly library by reusing captured SAML assertions, enabling them to impersonate legitimate users. This critical flaw arises from the lack of enforcement of the SAML 2.0 requirement for single-use assertions, making it possible for attackers to repeatedly authenticate until the assertion expires. Organizations utilizing the Samly library version 0.3.0 or later should prioritize remediation to prevent unauthorized access to their systems.

CVE
CVE-2026-53424
Severity
CRITICAL
CVSS
9.1
EPSS
0.34%

Original NVD Description

Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_resp/3 in lib/samly/helper.ex calls esaml_sp:validate_assertion/2, whose default duplicate detector is a no-op. The /3 arity accepting a DuplicateFun exists in esaml and implements the check, but Samly never calls it and offers no configuration to supply one, so the SAML 2.0 Web Browser SSO Profile requirement that a bearer assertion be used once is unenforced. An attacker holding a valid SAMLResponse obtained from the network, from browser history, or from logs can submit the identical bytes repeatedly until the assertion's NotOnOrAfter passes, each time establishing a session as the assertion's subject. This issue affects samly: from 0.3.0 onward.