Back

MEDIUM

Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0

Published Jul 9, 2026

Description

An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can craft a request to the SAML sign-in endpoint and poison the cached SAML redirection for other users who subsequently initiate SAML Single Sign-On, enabling phishing and credential-theft attacks, as well as disrupting SAML authentication for all affected users.

Affected products

Remediation

Vendor solution

Upgrade to v26.2.0 or later.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Nozomi
Published Jul 9, 2026
Updated Aug 11, 2026
Reserved Mar 10, 2026
CISA Vulnrichment
Updated Jul 9, 2026
NVD
Status Modified
Modified Aug 11, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Nozomi
Published Jul 9, 2026
Updated Aug 11, 2026
Exploited since n/a
EUVD-2026-42532