SAML 2.0
Security Assertion Markup Language. An XML-based protocol for federated authentication, dominant in enterprise SSO. Largely superseded by OIDC for new deployments but still required for legacy SaaS app catalogs.
SAML is not going away because the enterprise buyer on the other side of a B2B deal requires it, which is why every serious CIAM platform still ships it. Its security record is worse than OIDC's for a structural reason: XML signature validation is genuinely hard, and canonicalization and parser-differential bugs have produced a long run of authentication bypasses where a service provider accepted a forged assertion.
See also: SAML 2.0, SAML vs OIDC, federation, identity CVE catalog
Related on Start with Identity
- GlossaryAuthorization Server
In OAuth 2.0, the component that authenticates the resource owner, obtains their authorization, and issues access tokens to clients. It exposes the authorizatio
- GlossaryKerberos
A ticket-based network authentication protocol using symmetric cryptography and a trusted third party, the Key Distribution Center. A client authenticates once,
- GlossaryLDAP
Lightweight Directory Access Protocol. A protocol for querying and modifying a hierarchical directory of entries, each identified by a distinguished name. Used
- CVEFortiCloud SSO SAML bypass on FortiOS, FortiProxy, FortiSwitchManager
A crafted SAML message bypasses FortiCloud SSO (CWE-347). Arctic Wolf saw malicious logins three days after disclosure. CISA added it to KEV on 16 December 2025
- CVEFortinet follow-on SSO SAML bypass after the 59718 patch
A second FortiCloud SSO SAML bypass that hits devices already patched for CVE-2025-59718 and CVE-2025-59719. Actively exploited. CISA guidance 28 January 2026.
- CVEFortiWeb FortiCloud SSO SAML bypass
The FortiWeb twin of CVE-2025-59718. A crafted SAML message bypasses FortiCloud SSO on FortiWeb. Same CWE-347 class, same December 2025 window, same 'patch or d