Improper access control in SAML - CVE-2026-84668
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the @DataBoundConstructor annotation. A remote user can overwrite the SAML identity provider metadata with attacker-controlled content without the required permission.