Junglewise Threat Intelligence

CVE-2026-73784: HPE IceWall SAML response tampering vulnerability

CVE-2026-73784 · Severity: high · CVSS 8.8 · Published 2026-09-11

Vendors: Hpe.

Executive brief

HPE IceWall is an authentication and identity management system used to control user access to corporate applications and services. A vulnerability in SAML response handling allows attackers to tamper with authentication tokens, enabling them to impersonate legitimate users and gain unauthorized access to protected resources without needing valid credentials.

Technical details

This vulnerability is a SAML response tampering issue affecting HPE IceWall's authentication mechanism. The vulnerability allows an attacker to modify SAML assertions used during the single sign-on (SSO) process, potentially bypassing cryptographic validation or exploiting insufficient signature verification. The attack vector is network-based and does not require authentication; an attacker can intercept or manipulate SAML responses to forge identity claims. Successful exploitation enables unauthorized impersonation of any user, granting access to all applications relying on the compromised identity provider. Patches are available from HPE.

Affected products

  • HPE IceWall

Timeline

  • 2026-09-11: disclosed

References