CVE-2020-26290Critical· 9.8▾ MidnightAuthentication Bypass in dex
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
1.0%
Last analysed / modified upstream
A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects dex versions before 2.27.0.
github.com/dexidp/dex < 2.27.0Upgrade to a patched release:
github.com/dexidp/dex 2.27.0Connected by shared product, vendor, weakness, or advisory.