<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T18:43:35.430332+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-336105</id>
    <title>EUVD-2026-336105</title>
    <updated>2026-10-09T18:43:35.433300+00:00</updated>
    <content>EUVD-2026-336105</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-336105"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59151</id>
    <title>fkie_cve-2026-59151</title>
    <updated>2026-10-09T18:43:35.433338+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token, and the ACS finish logic in api/src/backend/api/v1/views.py recalculated the tenant from user.email instead of binding token issuance to the validated SAML configuration. An authenticated attacker with a controlled SAML IdP could complete a valid SAML flow for an attacker-controlled domain while asserting an email address from another configured domain, causing a SAMLToken and tenant-scoped JWT to be issued for the wrong tenant and enabling cross-tenant account takeover. This issue is fixed in version 5.30.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h8m9-jgf8-vwvp</id>
    <title>GHSA-h8m9-jgf8-vwvp — Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover</title>
    <updated>2026-10-09T18:43:35.433377+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: prowler-cloud</p>
<p>## SAML Tenant Binding Enables Cross-Tenant Account Takeover</p>
<p>### Summary</p>
<p>Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token. A malicious tenant with its own SAML configuration and a self-controlled IdP could complete a valid SAML flow for its own configured domain, while asserting an email address from another configured domain.</p>
<p>In the vulnerable flow, the ACS finish logic later derived the tenant from the asserted email domain instead of binding token issuance to the tenant associated with the validated SAML configuration. This could cause a token to be issued for the wrong tenant.</p>
<p>The attacker does not generally need to claim the victim's email domain. If the victim tenant already has SAML configured for that domain, another tenant cannot claim it because `SAMLConfiguration.email_domain` and `SAMLDomainIndex.email_domain` are globally unique.</p>
<p>### Details
The confirmed root cause is in the SAML ACS finish and token issuance flow. The flow selected a SAML configuration through the ACS route, but later recalculated the tenant from the asserted user email domain:</p>
<p>```python
email_domain = user.email.split("@")[-1]
tenant = (
    SAMLConfiguration.objects.using(MainRouter.admin_db)
    .get(email_domain=email_domain)
    .tenant
)
```</p>
<p>This is unsafe because `user.email` is derived from the SAML assertion. The tenant used for membership updates and token issuance must come from th…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h8m9-jgf8-vwvp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3725</id>
    <title>PYSEC-2026-3725</title>
    <updated>2026-10-09T18:43:35.433491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: prowler-cloud</p>
<p>Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token, and the ACS finish logic in api/src/backend/api/v1/views.py recalculated the tenant from user.email instead of binding token issuance to the validated SAML configuration. An authenticated attacker with a controlled SAML IdP could complete a valid SAML flow for an attacker-controlled domain while asserting an email address from another configured domain, causing a SAMLToken and tenant-scoped JWT to be issued for the wrong tenant and enabling cross-tenant account takeover. This issue is fixed in version 5.30.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3725"/>
  </entry>
</feed>
