THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-h8m9-jgf8-vwvp (critical) — Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover

[GHSA] GHSA-h8m9-jgf8-vwvp (critical) — Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover

highgithub_advisoriesPublished 2026-09-11

GHSA-h8m9-jgf8-vwvp Severity: critical CVE: CVE-2026-59151

Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover

## SAML Tenant Binding Enables Cross-Tenant Account Takeover

### Summary

Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token. A malicious tenant with its own SAML configuration

Attributed threat actors

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-h8m9-jgf8-vwvp