Improper Certificate Validation in Apache CloudStack - CVE-2026-68745
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to forge SAML responses and log in to the management server.
The vulnerability exists due to improper certificate validation in SAML authentication when processing SAML responses from a certificate-less identity provider configuration. A remote attacker can spoof the identity provider address or use a registered URL under their control to forge SAML responses and log in to the management server.
The issue affects SAML authentication when signature validation is silently skipped.