CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-59151

Critical · CVSS 9.6

Prowler — SAML authentication bypass / cross-tenant account takeover (improper authentication CWE-287)

CVSS
9.6
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-287

Description

Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token, and the ACS finish logic in api/src/backend/api/v1/views.py recalculated the tenant from user.email instead of binding token issuance to the validated SAML configuration. An authenticated attacker with a controlled SAML IdP could complete a valid SAML flow for an attacker-controlled domain while asserting an email address from another configured domain, causing a SAMLToken and tenant-scoped JWT to be issued for the wrong tenant and enabling cross-tenant account takeover. This issue is fixed in version 5.30.3.

Search profile — drives PoC discovery

Symbols api/src/backend/api/v1/views.pyACS finish logicSAMLResponseSAMLTokenuser.emailtenant-scoped JWTSAML IdPprowler-cloud/prowler
Keywords CVE-2026-59151GHSA-h8m9-jgf8-vwvpProwler SAML authentication bypassProwler cross-tenant takeoverProwler SAMLToken tenant JWTProwler ACS SAML email domainprowler SAML IdP tenant misconfigurationprowler 5.30.3 fixbf3b5c2ba713e533014927141b64948c82c8f32ef5ff30ad175bd2edf02cd28872653c1cda5867b7
Versions: < 5.30.3

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-14T00:00:21.000Z · profiled 2026-07-14T00:30:21.000Z