Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-12281
Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Spoofing
CVE-2025-9943
Unauthenticated SQL Injection Vulnerability in Shibboleth Service Provider
CVE-2023-36661
XMLTooling: SSRF via a crafted KeyInfo element
CVE-2023-22947
Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. This occurs because the installation goes under C:\opt (rather than C:\Program Files) by default. NOTE: the vendor disputes the significance of this report, stating that "We consider the ACLs a best effort thing" and "it was a documentation mistake."
CVE-2022-24129
The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allows attackers to interact with arbitrary third-party HTTP services.
