As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-86304: MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-86304: MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor
MojoX::Authentication versions before 0.006 for Perl contain a SAML authentication bypass vulnerability (CVE-2026-86304) because the parse_assertion function builds Net::SAML2::Binding::POST without a trust anchor. Applications using affected versions are susceptible to unauthorized access through forged SAML assertions.
Why it matters: Perl developers and system administrators using MojoX::Authentication should upgrade to version 0.006 or later immediately to prevent attackers from bypassing SAML authentication and gaining unauthorized access to applications.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-86304: MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor
MojoX::Authentication versions before 0.006 for Perl contain a SAML authentication bypass vulnerability (CVE-2026-86304) because the parse_assertion function builds Net::SAML2::Binding::POST without a trust anchor. Applications using affected versions are susceptible to unauthorized access through forged SAML assertions.
Why it matters: Perl developers and system administrators using MojoX::Authentication should upgrade to version 0.006 or later immediately to prevent attackers from bypassing SAML authentication and gaining unauthorized access to applications.
- Source published
- First seen by Cybersecurity Tracker