An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can craft a request to the SAML sign-in endpoint and poison the cached SAML redirection for other users who subsequently initiate SAML Single Sign-On, enabling phishing and credential-theft attacks, as well as disrupting SAML authentication for all affected users.
References
| Link | Resource |
|---|---|
| https://security.nozominetworks.com/NN-2026:9-01 | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
10 Jul 2026, 13:14
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Nozominetworks
Nozominetworks cmc Nozominetworks guardian |
|
| References | () https://security.nozominetworks.com/NN-2026:9-01 - Mitigation, Vendor Advisory | |
| CPE | cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:* cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:* |
09 Jul 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-09 08:16
Updated : 2026-07-10 13:14
NVD link : CVE-2026-31982
Mitre link : CVE-2026-31982
CVE.ORG link : CVE-2026-31982
JSON object : View
Products Affected
nozominetworks
- cmc
- guardian
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
