Skip to main content
Vulnerability Database/CVE-2026-14917

CVE-2026-14917: Kong SAML Plugin Auth Bypass Vulnerability

CVE-2026-14917 is a SAML authentication bypass vulnerability in Kong SAML plugin that allows attackers to impersonate users without valid signatures. This article covers technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2026-14917 Overview

CVE-2026-14917 is a Security Assertion Markup Language (SAML) authentication bypass affecting the Kong SAML plugin. The flaw occurs when the validate_assertion_signature option is explicitly set to false. Under this configuration, the plugin extracts the SAML identity from an unsigned assertion and authenticates the user without verifying a valid cryptographic signature.

An unauthenticated remote attacker can submit a crafted SAML response and impersonate arbitrary users, including administrators. The vulnerability is classified under [CWE-288] Authentication Bypass Using an Alternate Path or Channel. The validate_assertion_signature option is enabled by default, so only operators who explicitly disabled signature validation are exposed.

Critical Impact

Unauthenticated attackers can forge SAML responses to impersonate any user, including administrators, on Kong deployments where validate_assertion_signature has been set to false.

Affected Products

  • Kong Gateway with the SAML plugin enabled
  • Deployments configured with validate_assertion_signature = false
  • Versions prior to Kong Gateway 3.15.0

Discovery Timeline

  • 2026-09-16 - CVE-2026-14917 published to the National Vulnerability Database (NVD)
  • 2026-09-16 - Last updated in NVD database

Technical Details for CVE-2026-14917

Vulnerability Analysis

SAML authentication relies on cryptographic signatures to prove that assertions originate from a trusted Identity Provider (IdP). The Kong SAML plugin exposes a configuration flag, validate_assertion_signature, that toggles signature validation on inbound assertions.

When an administrator sets this flag to false, the plugin still parses the assertion and extracts the identity attributes contained within it. The plugin then issues an authenticated session based on those extracted attributes, bypassing the trust boundary that a valid signature would normally enforce.

An attacker does not need to compromise the IdP or its signing key. The attacker simply crafts a SAML response containing any chosen NameID or attribute values and delivers it to the Kong SAML endpoint. Because no signature check is performed, the plugin accepts the forged identity as authoritative.

Root Cause

The root cause is insecure trust in unsigned SAML assertions when signature validation is disabled. The plugin treats the presence of an assertion as sufficient proof of identity, violating the SAML security model which requires cryptographic verification of any assertion consumed by a Service Provider.

Attack Vector

Exploitation occurs over the network with no privileges and no user interaction. The attacker sends a POST request to the Kong SAML Assertion Consumer Service endpoint containing an unsigned SAML response. The response carries attacker-chosen subject identifiers, such as an administrator username, which the plugin accepts and uses to establish an authenticated session.

No verified proof-of-concept code is publicly available. See the Kong Gateway Changelog 3.15.0 for vendor technical details.

Detection Methods for CVE-2026-14917

Indicators of Compromise

  • SAML responses arriving at Kong Assertion Consumer Service endpoints without valid ds:Signature elements
  • Authentication events for privileged accounts originating from unexpected IP addresses or geographies
  • Session establishment for users who did not perform a corresponding IdP-initiated login
  • Kong plugin configuration entries where validate_assertion_signature is set to false

Detection Strategies

  • Audit all Kong SAML plugin configurations for instances where validate_assertion_signature is explicitly false
  • Correlate Kong access logs with IdP authentication logs to identify sessions lacking a matching IdP login event
  • Inspect captured SAML responses for missing or malformed signature blocks on assertions and responses

Monitoring Recommendations

  • Ingest Kong Gateway access and admin API logs into a centralized SIEM for correlation with identity telemetry
  • Alert on any change to the validate_assertion_signature setting through the Kong Admin API or declarative configuration
  • Monitor for privilege escalation activity following successful SAML authentications, such as new admin API tokens or role changes

How to Mitigate CVE-2026-14917

Immediate Actions Required

  • Set validate_assertion_signature to true on every Kong SAML plugin instance and reject any configuration that disables it
  • Upgrade Kong Gateway to version 3.15.0 or later, which addresses this issue per the vendor changelog
  • Review authentication and admin activity logs since the plugin was deployed to identify potentially forged sessions
  • Rotate credentials, API keys, and admin sessions for any account that may have been impersonated

Patch Information

Kong addressed the issue in Kong Gateway 3.15.0. Refer to the Kong Gateway Changelog 3.15.0 for release notes and upgrade guidance.

Workarounds

  • Ensure validate_assertion_signature remains at its default value of true on all SAML plugin instances
  • Enforce signature validation policy through configuration management to prevent operator drift
  • Restrict access to the Kong Admin API so that plugin configuration cannot be modified by unauthorized users
bash
# Kong SAML plugin configuration - enforce assertion signature validation
curl -X PATCH http://localhost:8001/plugins/{plugin-id} \
  --data "config.validate_assertion_signature=true"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.