CVE-2026-31982
EUVD-2026-4253209.07.2026, 08:16
An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can craft a request to the SAML sign-in endpoint and poison the cached SAML redirection for other users who subsequently initiate SAML Single Sign-On, enabling phishing and credential-theft attacks, as well as disrupting SAML authentication for all affected users.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nozominetworks | cmc | 𝑥 < 26.2.0 |
| nozominetworks | guardian | 𝑥 < 26.2.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Siemens | RUGGEDCOM APE1808 | 𝑥 < * | ADP |
Common Weakness Enumeration