Executive brief
MojoX::Authentication is a Perl module that handles SAML-based single sign-on (SSO) authentication. Versions before 0.006 fail to properly validate SAML responses, allowing an attacker to forge authentication by signing a response with their own certificate. An attacker can gain unauthorized access to any account without knowing passwords, potentially compromising systems that rely on this module for identity verification.
Technical details
The vulnerability is an authentication bypass in the SAML assertion parsing logic. The parse_assertion method in MojoX::Authentication::Model::SAML2 initializes Net::SAML2::Binding::POST without configuring a trust anchor (cacert, cert_text, or anchors parameter), then validates the XML signature against a certificate contained within the SAML response itself rather than a pre-configured IdP certificate. This allows an attacker to craft a valid SAML assertion signed with their own certificate. The follow-up validation checks (audience, InResponseTo, timestamp) can be satisfied by the attacker, leading to authentication of any NameID without possessing legitimate credentials. The vulnerability requires network access to initiate a SAML login flow but requires no user interaction beyond normal authentication. Patches are available in MojoX::Authentication 0.006 and Net::SAML2 0.86.
Affected products
- MojoX::Authentication MojoX::Authentication before 0.006
- Net::SAML2 Net::SAML2 before 0.86
Timeline
- 2026-09-06: disclosed