THREAT OPS › Threat News › [GHSA] GHSA-h8m9-jgf8-vwvp (critical) — Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
[GHSA] GHSA-h8m9-jgf8-vwvp (critical) — Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
GHSA-h8m9-jgf8-vwvp Severity: critical CVE: CVE-2026-59151
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
## SAML Tenant Binding Enables Cross-Tenant Account Takeover
### Summary
Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token. A malicious tenant with its own SAML configuration
Attributed threat actors
- SilenceG0091
MITRE ATT&CK techniques
- Verify AttackAML.T0042
Indicators of compromise
- CVE-2026-59151cve
- user@victim.comemail
- victim@victim.comemail
- attacker@evil-corp.comemail
- attacker.comdomain
Original source: https://github.com/advisories/GHSA-h8m9-jgf8-vwvp