# HaloITSM SAML signature wrapping, log in as any user

Source: https://startwithidentity.com/cves/cve-2024-6202/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

HaloITSM's [SAML](https://startwithidentity.com/glossary/saml/) verifier did not bind the XML signature to the assertion it consumed. An attacker with one valid signature constructed a new assertion and logged in as any user, including administrators. Critical. Vendor patched.

## Why it matters

ITSM is where password resets, joiner tickets, and break-glass live. Impersonating an ITSM admin is an identity incident even if the corporate [IdP](https://startwithidentity.com/glossary/identity-provider/) is fine. 2024's wrapping list is not only libraries. It is every SP that rolled its own XML.

## What to do

- Patch HaloITSM. If SAML was on while unpatched, review new admin agents and unexpected password-reset tickets.
- Treat ITSM SSO as tier-zero, the same way you treat the [Okta support-system](https://startwithidentity.com/breaches/okta-2023-support-system-breach/) plane.
- Ask the vendor which SAML stack they use. If the answer is "a PHP XML parser we wrote," assume wrapping until shown otherwise.

## After you patch

A SAML bypass means the service provider accepted an assertion it should have rejected, so anyone who exploited it authenticated as a real user and left a normal-looking log line.

- **Revoke every session** issued by the affected service provider, then rotate its session signing keys. Patching stops new forgeries and does nothing about sessions already minted.
- **Audit administrative accounts and group memberships** for changes during the exposure window. Signing in as an administrator is the point of this class, and adding a second account is the standard persistence step.
- **Rotate the identity provider signing certificate** if the flaw involved signature validation, and confirm the service provider pins the expected certificate rather than trusting anything in the assertion.
- **Check your own implementation for the same class**: exact-match comparison on verification results, rejection of unexpected signature algorithms, and audience and recency checks on every assertion. See [SAML 2.0](https://startwithidentity.com/standards/saml-2-0/) and [SAML vs OIDC](https://startwithidentity.com/guides/fundamentals/saml-vs-oidc/).

## Sources

- [NVD: CVE-2024-6202](https://nvd.nist.gov/vuln/detail/CVE-2024-6202)
