#SSO
All CosmicBytez Labs articles tagged #SSO, across news, security advisories, how-to guides, and projects.
- Security
Frontegg SAML SSO Plugin Flaw Lets Anyone Log In as WordPress Admin
CVE-2026-75800 lets unauthenticated attackers forge SAML responses and log in as any WordPress user, including administrators.
- News
Dropbox Accounts Breached Through Lenovo Email Verification Flaw
A flaw in Lenovo's email verification let attackers register fake Lenovo IDs and silently access ~5,000 Dropbox accounts via SSO.
- Security
CVE-2026-15013: WordPress SAML SSO Plugin — Algorithm Confusion Auth Bypass
The miniOrange SAML Single Sign On plugin for WordPress through version 5.4.3 allows unauthenticated attackers to log in as any user via an RSA-to-HMAC...
- Security
CVE-2026-11374: ManageEngine SSO Ticket Prediction Enables Unauthenticated Account Takeover
A critical authentication vulnerability in four ManageEngine products allows unauthenticated attackers to predict SSO session tickets and take over...
- Project
Keycloak SSO: Self-Hosted Identity Provider for Your Homelab
Deploy Keycloak with Docker Compose and PostgreSQL to build a centralised single sign-on platform for your homelab services, with OIDC integration for...
- HOWTO
Multi-Stack Docker Infrastructure with Traefik and Authentik
Deploy a production-grade Docker infrastructure with Traefik reverse proxy, Authentik single sign-on, automated TLS certificates, and multi-network...