
🚨 CRITICAL - Prowler SAML tenant confusion leads to cross-tenant token issuance (CVE-2026-59151) Prowler’s SAML authentication flow prior to 5.30.3 incorrectly trusts the email domain asserted in the SAMLResponse to select the tenant, impacting the ACS finish logic and token issuance path. The root cause is improper authentication binding/tenant confusion: the app recalculates tenant from http://user.email instead of binding the session and token issuance to the validated SAML configuration for that tenant. An authenticated attacker who controls a SAML IdP (or can influence SAML assertions) can submit a SAMLResponse asserting an email from another configured domain to force token issuance for the wrong tenant. Successful exploitation results in issuance of a SAMLToken and tenant-scoped JWT for another tenant, enabling cross-tenant account takeover and unauthorized access to tenant data and actions. 👉 Affected: prowler < 5.30.3 | Upgrade to 5.30.3
Post summary
The advisory details a critical Prowler SAML tenant confusion flaw that permits cross‑tenant token issuance and account takeover, and it advises upgrading to version 5.30.3 to remediate the issue.
