CVE-2025-54982: SAML 2.0 Public Key Validation Issue
Published Aug 5, 2025
·Updated
An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse.
Affected Software
1 affected component
Zscaler SAML authentication mechanism
Event History
Aug 5, 2025
CVE Published
via MITRE·05:36 AM
Data Sourced
via MITRE·05:36 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-54982?
CVE-2025-54982 has been rated with a high severity due to the potential for authentication abuse.
2
How do I fix CVE-2025-54982?
To fix CVE-2025-54982, ensure that your Zscaler SAML authentication mechanism is updated to the latest version provided by Zscaler.
3
What kind of impact does CVE-2025-54982 have on systems?
CVE-2025-54982 can lead to unauthorized access, allowing attackers to bypass authentication mechanisms.
4
Is CVE-2025-54982 specific to certain versions of Zscaler SAML authentication?
CVE-2025-54982 affects all implementations of Zscaler's SAML authentication mechanism, regardless of version.
5
Are there any workarounds for CVE-2025-54982 pending a fix?
There are currently no documented workarounds for CVE-2025-54982; applying the latest update is recommended.