ZeroHour

CVE-2026-73784

niche

Improper SAML Signature Verification in HPE IceWall Allows User Impersonation

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

HPE has disclosed a high-severity flaw (CVE-2026-73784, CWE-347) in its IceWall product line involving improper verification of the cryptographic signatures that protect SAML responses. An attacker with network access and low-level privileges could tamper with a SAML response — for example, altering assertion content such as the asserted user identity — because the signature is not correctly validated, and no user interaction is required. Successful exploitation lets the attacker impersonate another user at the relying service, gaining that user's access with high impact on confidentiality and integrity. Any organization running affected HPE IceWall products that processes SAML federated authentication is affected; the available data does not enumerate specific product versions. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.

What to do: Patch all IceWall components per the HPE security bulletin for CVE-2026-73784, which lists the affected and fixed releases (exact versions are not included in the data provided here). Inventory environments where IceWall acts as a SAML identity provider or service provider, prioritizing those federating with external partners or exposed to untrusted networks. Review authentication logs for logins backed by SAML assertions with unexpected user identifiers or attributes, and for accounts accessed from atypical sources, as possible evidence of prior tampering.

Affected
HPE IceWall products (SAML federation components)
Estimated exposure
nicheunknown; plausibly thousands to tens of thousands of enterprise end users, concentrated in Japanese enterprise and government SSO deployments — HPE IceWall is an enterprise single sign-on/SAML federation product sold primarily into Japanese enterprises and public-sector organizations, and no public install counts are available, so only the deployment pattern supports the estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.

Weakness
CWE-347
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.