{"id":"PYSEC-2026-3725","details":"Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token, and the ACS finish logic in api/src/backend/api/v1/views.py recalculated the tenant from user.email instead of binding token issuance to the validated SAML configuration. An authenticated attacker with a controlled SAML IdP could complete a valid SAML flow for an attacker-controlled domain while asserting an email address from another configured domain, causing a SAMLToken and tenant-scoped JWT to be issued for the wrong tenant and enabling cross-tenant account takeover. This issue is fixed in version 5.30.3.","aliases":["CVE-2026-59151","GHSA-h8m9-jgf8-vwvp"],"modified":"2026-08-28T02:30:02.735987563Z","published":"2026-07-10T19:17:26.780Z","references":[{"type":"ADVISORY","url":"https://github.com/prowler-cloud/prowler/releases/tag/5.30.3"},{"type":"REPORT","url":"https://github.com/prowler-cloud/prowler/pull/11650"},{"type":"FIX","url":"https://github.com/prowler-cloud/prowler/commit/bf3b5c2ba713e533014927141b64948c82c8f32e"},{"type":"FIX","url":"https://github.com/prowler-cloud/prowler/commit/f5ff30ad175bd2edf02cd28872653c1cda5867b7"},{"type":"EVIDENCE","url":"https://github.com/prowler-cloud/prowler/security/advisories/GHSA-h8m9-jgf8-vwvp"}],"affected":[{"package":{"name":"prowler-cloud","ecosystem":"PyPI","purl":"pkg:pypi/prowler-cloud"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.30.3"}]}],"versions":["0.0.0rc1","0.0.0rc10","0.0.0rc11","0.0.0rc2","0.0.0rc3","0.0.0rc4","0.0.0rc5","0.0.0rc6","0.0.0rc7","0.0.0rc8","0.0.0rc9","3.0.0","3.0.0rc1","3.0.0rc11","3.0.0rc12","3.0.0rc13","3.0.0rc14","3.0.0rc15","3.0.1","3.0.2","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.10.0","3.11.0","3.11.1","3.11.2","3.11.3","3.12.0","3.12.1","3.13.0","3.13.1","3.14.0","3.15.0","3.15.1","3.15.2","3.15.3","3.16.0","3.16.1","3.16.10","3.16.11","3.16.12","3.16.13","3.16.14","3.16.15","3.16.17","3.16.2","3.16.3","3.16.4","3.16.5","3.16.6","3.16.7","3.16.8","3.16.9","3.2.0","3.2.1","3.2.2","3.2.3","3.2.4","3.3.0","3.3.1","3.3.2","3.3.3","3.3.4","3.4.0","3.4.1","3.5.0","3.5.1","3.5.2","3.5.3","3.6.0","3.6.1","3.7.0","3.7.1","3.7.2","3.8.0","3.8.1","3.8.2","3.9.0","4.0.0","4.0.1","4.1.0","4.2.0","4.2.1","4.2.2","4.2.3","4.2.4","4.3.0","4.3.1","4.3.2","4.3.3","4.3.4","4.3.5","4.3.6","4.3.7","4.4.0","4.4.1","4.5.0","4.5.1","4.5.2","4.5.3","4.6.0","4.6.1","4.6.2","5.0.0","5.0.1","5.0.2","5.0.3","5.0.4","5.0.5","5.1.0","5.1.1","5.1.2","5.1.3","5.1.4","5.1.5","5.10.0","5.10.1","5.10.2","5.11.0","5.12.0","5.12.1","5.12.2","5.12.3","5.13.0","5.13.1","5.14.0","5.14.1","5.14.2","5.15.0","5.15.1","5.16.0","5.16.1","5.17.0","5.17.1","5.18.0","5.18.1","5.18.2","5.18.3","5.19.0","5.2.0","5.2.1","5.2.2","5.2.3","5.20.0","5.21.0","5.21.1","5.22.0","5.23.0","5.24.0","5.24.1","5.24.2","5.24.3","5.24.4","5.25.0","5.25.1","5.25.2","5.25.3","5.26.0","5.26.1","5.27.0","5.27.1","5.28.0","5.28.1","5.29.0","5.29.1","5.29.2","5.3.0","5.30.0","5.30.1","5.30.2","5.4.0","5.4.1","5.4.2","5.4.3","5.4.4","5.5.1","5.6.0","5.7.0","5.7.1","5.7.2","5.7.3","5.7.4","5.7.5","5.8.0","5.8.1","5.9.0","5.9.1","5.9.2"],"ecosystem_specific":{},"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/prowler-cloud/PYSEC-2026-3725.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}