How to use this reference
Keep federation configuration, accepted identity claims, membership changes and issued-token tenant consistent. The advisory lists Prowler API through 5.30.2 as affected and 5.30.3 as patched; no patch-release date is established here.
Before reading
- Basic federation and object-level authorization concepts
Context and limits
- Requires SAML, authenticated control of a tenant configuration and identity provider, and a target domain mapped to another SAML tenant; no victim interaction.
- Configured domains remain globally unique. The advisory narrative corrects conflicting older demonstration comments.
- Credits: EQSTLab, reporter; AdriiiPRodri, remediation developer; jfagoagas, coordinator/publishing account; josema-xyz, analyst. Article authorship is not established.
- Broader access and persistence are potential consequences. The fix was not independently audited.
- The displayed test mocks the linking method and checks its invocation with an existing user; it is narrower evidence than completed persistent linking.
Sources and provenance
- SAML Domain Claiming Enables Cross-Tenant Account Takeover Prowler · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.