THREAT OPS › Threat News › CVE-2026-86304: MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor
CVE-2026-86304: MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor
<p>Posted by Timothy Legge on Sep 06</p>========================================================================<br /> CVE-2026-86304 CPAN Security Group<br /> ========================================================================<br /> <br /> CVE ID: CVE-2026-86304<br /> Distribution: MojoX-Authentication<br /> Versions: before 0.006<b
Indicators of compromise
- CVE-2026-86304cve
- https://metacpan.org/dist/MojoX-Authenticationurl
Original source: https://seclists.org/oss-sec/2026/q3/662