Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0
Published Jul 9, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.31%
Description
An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can craft a request to the SAML sign-in endpoint and poison the cached SAML redirection for other users who subsequently initiate SAML Single Sign-On, enabling phishing and credential-theft attacks, as well as disrupting SAML authentication for all affected users.
Affected products
-
- Version 0StatusaffectedConstraints<26.2.0
- Version
-
- Version 0StatusaffectedConstraints<26.2.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Nozomi Networks | CMC | unaffected |
| ||||||
| Nozomi Networks | Guardian | unaffected |
|
- < 26.2.0
- < 26.2.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to v26.2.0 or later.
References (3)
- https://cert-portal.siemens.com/productcert/html/ssa-827968.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42532 Advisory
- https://security.nozominetworks.com/NN-2026:9-01 MitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-827968.html | ||
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42532 | Advisory | |
| https://security.nozominetworks.com/NN-2026:9-01 | MitigationVendor Advisory |
Change history (0)
No recorded changes yet.