CVE-2026-28809 | dropbox/arekinath/handnot2 esaml SAML xml external entity reference
VulDBArchived Mar 23, 2026✓ Full text saved
A vulnerability, which was classified as problematic , was found in dropbox/arekinath/handnot2 esaml . This affects an unknown part of the component SAML Handler . Such manipulation leads to xml external entity reference. This vulnerability is listed as CVE-2026-28809 . The attack may be performed from remote. There is no available exploit. You should upgrade the affected component.
Full text archived locally
✦ AI Summary· Claude Sonnet
VDB-352509 · CVE-2026-28809 · GCVE-0-2026-28809
DROPBOX/AREKINATH/HANDNOT2 ESAML SAML XML EXTERNAL ENTITY REFERENCE
HISTORYDIFFRELATEJSONXMLCTI
CVSS Meta Temp Score Current Exploit Price (≈) CTI Interest Score
6.0 $0-$5k 3.27+
Summaryinfo
A vulnerability has been found in dropbox/arekinath/handnot2 esaml and classified as problematic. This vulnerability affects unknown code of the component SAML Handler. Performing a manipulation results in xml external entity reference. This vulnerability is cataloged as CVE-2026-28809. It is possible to initiate the attack remotely. There is no exploit available. The affected component should be upgraded.
Detailsinfo
A vulnerability was found in dropbox/arekinath/handnot2 esaml (the affected version unknown). It has been classified as critical. This affects an unknown part of the component SAML Handler. The manipulation with an unknown input leads to a xml external entity reference vulnerability. CWE is classifying the issue as CWE-611. The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. This is going to have an impact on confidentiality, integrity, and availability. The summary by CVE is:
XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML documents, and potentially perform SSRF via crafted SAML messages. esaml parses attacker-controlled SAML messages using xmerl_scan:string/2 before signature verification without disabling XML entity expansion. On Erlang/OTP versions before 27, Xmerl allows entities by default, enabling pre-signature XXE attacks. An attacker can cause the host to read local files (e.g., Kubernetes-mounted secrets) into the SAML document. If the attacker is not a trusted SAML SP, signature verification will fail and the document is discarded, but file contents may still be exposed through logs or error messages. This issue affects all versions of esaml, including forks by arekinath, handnot2, and dropbox. Users running on Erlang/OTP 27 or later are not affected due to Xmerl defaulting to entities disabled.
The weakness was shared by Bryan Lynch. The advisory is shared at cna.erlef.org. This vulnerability is uniquely identified as CVE-2026-28809 since 03/03/2026. The exploitability is told to be easy. It is possible to initiate the attack remotely. Neither technical details nor an exploit are publicly available.
Upgrading eliminates this vulnerability.
Productinfo
Type
Cloud Software
Vendor
arekinath
dropbox
handnot2
Name
esaml
CPE 2.3info
🔒
🔒
🔒
CPE 2.2info
🔒
🔒
🔒
CVSSv4info
VulDB Vector: 🔒
VulDB Reliability: 🔍
CNA CVSS-B Score: 🔒
CNA CVSS-BT Score: 🔒
CNA Vector: 🔒
CVSSv3info
VulDB Meta Base Score: 6.3
VulDB Meta Temp Score: 6.0
VulDB Base Score: 6.3
VulDB Temp Score: 6.0
VulDB Vector: 🔒
VulDB Reliability: 🔍
CVSSv2info
Vector Complexity Authentication Confidentiality Integrity Availability
Unlock Unlock Unlock Unlock Unlock Unlock
Unlock Unlock Unlock Unlock Unlock Unlock
Unlock Unlock Unlock Unlock Unlock Unlock
VulDB Base Score: 🔒
VulDB Temp Score: 🔒
VulDB Reliability: 🔍
Exploitinginfo
Class: Xml external entity reference
CWE: CWE-611 / CWE-610
CAPEC: 🔒
ATT&CK: 🔒
Physical: No
Local: No
Remote: Yes
Availability: 🔒
Status: Not defined
Price Prediction: 🔍
Current Price Estimation: 🔒
0-Day Unlock Unlock Unlock Unlock
Today Unlock Unlock Unlock Unlock
Threat Intelligenceinfo
Interest: 🔍
Active Actors: 🔍
Active APT Groups: 🔍
Countermeasuresinfo
Recommended: Upgrade
Status: 🔍
0-Day Time: 🔒
Timelineinfo
03/03/2026 CVE reserved
03/23/2026 +20 days Advisory disclosed
03/23/2026 +0 days VulDB entry created
03/23/2026 +0 days VulDB entry last update
Sourcesinfo
Advisory: cna.erlef.org
Researcher: Bryan Lynch
Status: Confirmed
CVE: CVE-2026-28809 (🔒)
GCVE (CVE): GCVE-0-2026-28809
GCVE (VulDB): GCVE-100-352509
Entryinfo
Created: 03/23/2026 13:59
Changes: 03/23/2026 13:59 (67)
Complete: 🔍
Cache ID: 99:E8D:101
Discussion
No comments yet. Languages: en.
Please log in to comment.
◂ PreviousOverviewNext ▸