CVE-2026-49284 Details
Description
SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSAMLphp's SAML SP ACS path does not enforce the IdP selected for an SP-initiated login when unsigned Response/InResponseTo is combined with a signed assertion lacking SubjectConfirmationData/InResponseTo, allowing a response issued by one trusted IdP to be bound to SP state created for another IdP and bypass flows that route users to a specific IdP, including deployments that set enable_unsolicited to false. This issue is fixed in versions 2.4.7 and 2.5.2.
A vulnerability allowing information disclosure exists in SimpleSAMLphp versions prior to 1.18.6. In versions prior to 2.4.7 and 2.5.2, the SAML Service Provider (SP) Assertion Consumer Service (ACS) path fails to properly enforce the Identity Provider (IdP) selected for SP-initiated logins. This issue arises when an unsigned Response or InResponseTo is paired with a signed assertion that lacks SubjectConfirmationData or InResponseTo. As a result, a response from one trusted IdP can be incorrectly associated with SP state from another IdP, bypassing flows that direct users to specific IdPs, including those with unsolicited logins disabled.
Users can upgrade to SimpleSAMLphp versions 2.4.7 or 2.5.2 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/simplesamlphp/simplesamlphp/releases/tag/v2.4.7 | [email protected] | ProductRelease Notes |
| https://github.com/simplesamlphp/simplesamlphp/releases/tag/v2.5.2 | [email protected] | ProductRelease Notes |
| https://github.com/simplesamlphp/simplesamlphp/security/advisories/GHSA-q8r6-xj3f-wrrm | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| simplesamlphp simplesamlphp | < 2.4.7 >= 2.5.0, < 2.5.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | Initial Analysis | [email protected] |
| Jul 20, 2026 | CVE Modified | CISA-ADP |
| Jul 17, 2026 | New CVE Received | [email protected] |