vulns.co
/
GKData.io MCP

Prowler · 1 min read

Prowler SAML: retain validated tenant authority

CVE-2026-59151 concerns token issuance selecting a tenant from an asserted email domain instead of retaining the validated SAML configuration. Maintainers describe potential cross-tenant account takeover. Their adapter-level linking-call demonstration does not establish persisted account linkage, complete token issuance or production compromise.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Keep federation configuration, accepted identity claims, membership changes and issued-token tenant consistent. The advisory lists Prowler API through 5.30.2 as affected and 5.30.3 as patched; no patch-release date is established here.

Before reading

  • Basic federation and object-level authorization concepts

Context and limits

  • Requires SAML, authenticated control of a tenant configuration and identity provider, and a target domain mapped to another SAML tenant; no victim interaction.
  • Configured domains remain globally unique. The advisory narrative corrects conflicting older demonstration comments.
  • Credits: EQSTLab, reporter; AdriiiPRodri, remediation developer; jfagoagas, coordinator/publishing account; josema-xyz, analyst. Article authorship is not established.
  • Broader access and persistence are potential consequences. The fix was not independently audited.
  • The displayed test mocks the linking method and checks its invocation with an existing user; it is narrower evidence than completed persistent linking.

Sources and provenance

  1. SAML Domain Claiming Enables Cross-Tenant Account Takeover Prowler · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software