Authentication-bypass
2 posts tagged with “Authentication-bypass”

cveapache-artemisactivemq-artemis
CVE-2026-57967: unauth Artemis CORE session steal and OpenWire queue delete
How to fix CVE-2026-57967: upgrade Apache Artemis / ActiveMQ Artemis to 2.57.0. Unauth CORE SESSION_REATTACH can steal a live session; OpenWire RemoveSubscriptionInfo can delete queues before auth.
Sep 10, 2026
Read 
cvesecurityvulnerability
CVE-2026-18108: Net::SAML2 Authentication Bypass via Unsigned Encrypted Assertions (CVSS 9.8)
Net::SAML2 before 0.86 accepts decrypted SAML assertions that carry no XML signature. Any party can encrypt an unsigned assertion to an SP's published certificate and authenticate as an arbitrary user. Affects Azure AD, Okta, Google, ADFS, and all other IdPs.
Aug 4, 2026
Read