THREATOPS
THREAT OPSThreat News › CVE-2026-86304: MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor

CVE-2026-86304: MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor

medoss_secPublished 2026-09-06

<p>Posted by Timothy Legge on Sep 06</p>========================================================================<br /> CVE-2026-86304 CPAN Security Group<br /> ========================================================================<br /> <br /> CVE ID: CVE-2026-86304<br /> Distribution: MojoX-Authentication<br /> Versions: before 0.006<b

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/662

Same event, other sources