Industry
Aerospace & Public Sector
Timeline
Coordinated Disclosure (July 2026)
SAML Signature Confusion and SSO Authentication Bypass
Challenge
A large public sector organization's web portal utilized a SAML Single Sign-On (SSO) integration that exposed administrators to unauthenticated impersonation attacks.
Our Approach
Performed metadata verification and black-box signature algorithm analysis on SAML request and response handlers.
Impact Found
Identified an unpatched signature confusion vulnerability exposure (CVE-2026-15013) that allowed forging SAML assertions using the IdP's public key as an HMAC shared secret, enabling complete takeover of administrative accounts.
Outcome
Coordinated responsible disclosure via the organization's VDP. The vulnerability was mitigated by restricting signature verification algorithms to asymmetric schemes.