CVE-2026-73784
nicheImproper SAML Signature Verification in HPE IceWall Allows User Impersonation
HPE has disclosed a high-severity flaw (CVE-2026-73784, CWE-347) in its IceWall product line involving improper verification of the cryptographic signatures that protect SAML responses. An attacker with network access and low-level privileges could tamper with a SAML response — for example, altering assertion content such as the asserted user identity — because the signature is not correctly validated, and no user interaction is required. Successful exploitation lets the attacker impersonate another user at the relying service, gaining that user's access with high impact on confidentiality and integrity. Any organization running affected HPE IceWall products that processes SAML federated authentication is affected; the available data does not enumerate specific product versions. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.
What to do: Patch all IceWall components per the HPE security bulletin for CVE-2026-73784, which lists the affected and fixed releases (exact versions are not included in the data provided here). Inventory environments where IceWall acts as a SAML identity provider or service provider, prioritizing those federating with external partners or exposed to untrusted networks. Review authentication logs for logins backed by SAML assertions with unexpected user identifiers or attributes, and for accounts accessed from atypical sources, as possible evidence of prior tampering.
| HPE IceWall products (SAML federation components) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.
- Weakness
- CWE-347
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.