VYPR

Kong SAML plugin

by Kong

CVEs (1)

  • CVE-2026-14917HigSep 16, 2026
    risk 0.50cvss epss

    A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity from an unsigned assertion and authenticate…