CVE-2026-59151Patch(prowler / prowler)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch prowler prowler systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token, and the ACS finish logic in api/src/backend/api/v1/views.py recalculated the tenant from user.email instead of binding token issuance to the validated SAML configuration. An authenticated attacker with a controlled SAML IdP could complete a valid SAML flow for an attacker-controlled domain while asserting an email address from another configured domain, causing a SAMLToken and tenant-scoped JWT to be issued for the wrong tenant and enabling cross-tenant account takeover. This issue is fixed in version 5.30.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • prowler

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
prowler

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-11: 1Patch / Workaround · 2026-07-11: 1Technical Details · 2026-07-11: 107-11
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 CRITICAL - Prowler SAML tenant confusion leads to cross-tenant token issuance (CVE-2026-59151) Prowler’s SAML authentication flow prior to 5.30.3 incorrectly trusts the email domain asserted in the SAMLResponse to select the tenant, impacting the ACS finish logic and token issuance path. The root cause is improper authentication binding/tenant confusion: the app recalculates tenant from http://user.email instead of binding the session and token issuance to the validated SAML configuration for that tenant. An authenticated attacker who controls a SAML IdP (or can influence SAML assertions) can submit a SAMLResponse asserting an email from another configured domain to force token issuance for the wrong tenant. Successful exploitation results in issuance of a SAMLToken and tenant-scoped JWT for another tenant, enabling cross-tenant account takeover and unauthorized access to tenant data and actions. 👉 Affected: prowler < 5.30.3 | Upgrade to 5.30.3

    Post summary

    The advisory details a critical Prowler SAML tenant confusion flaw that permits cross‑tenant token issuance and account takeover, and it advises upgrading to version 5.30.3 to remediate the issue.

    00011107
    247 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprowlerprowler---

Explore more