Authentication Bypass in Zenth Core Identity Platform
Executive Summary
A critical authentication bypass vulnerability has been identified in Zenth Core Identity Platform (ZCIP) versions 4.8.0 through 4.8.11. The flaw allows an unauthenticated, remote attacker to forge valid session tokens by exploiting an improper cryptographic signature validation routine in the SAML/OIDC bridge module.
This vulnerability affects multiple Aevum Zenth divisions utilizing the centralized identity stack, including Zenth Digital Systems, Aevum Capital Group, and Zenth Health Sciences. Immediate patching is required for all affected deployments.
Technical Details
The vulnerability exists in auth/bridge/saml_validator.rs within the ZCIP authentication service. During token validation, the cryptographic signature verification step improperly handles null-byte termination in PEM-formatted public keys, allowing attackers to inject malformed certificates that bypass RSA-SHA256 validation.
Affected Components:
- Zenth Core Identity Platform v4.8.0 – v4.8.11
- Zenth Unified Access Gateway (ZUAG) v2.1.4 – v2.1.7
- Legacy SAML 2.0 Federation Modules (pre-2025)
Exploit Conditions: Remote, unauthenticated network access to the identity endpoint. No user interaction required. Attack vector: HTTP POST to /auth/validate.
Impact Assessment
Successful exploitation grants full administrative privileges to targeted identity domains. Attackers can:
- Forge authenticated sessions for privileged service accounts
- Escalate privileges across federated enterprise directories
- Access restricted data pipelines in Healthcare and Financial divisions
- Bypass multi-factor authentication controls
Aevum Zenth's Threat Intelligence Unit has not observed active exploitation in the wild, but the attack surface warrants urgent remediation.
Mitigation & Patch
Recommended Action
All administrators must upgrade to ZCIP v4.8.12 or later. The patch includes strict PEM parsing, explicit signature rejection on malformed certificates, and enhanced token rotation enforcement.
Temporary Workaround: If immediate patching is not feasible, restrict access to the /auth/validate endpoint via firewall rules to known internal CIDR blocks and enforce mutual TLS (mTLS) at the ingress layer.
Disclosure Timeline
Report a Vulnerability
Aevum Zenth maintains a responsible disclosure program for all subsidiaries and technology products. If you believe you have discovered a security vulnerability, please contact our security team immediately.
security@aezumzenth.comPGP Key: 0xA7B2 9C41 88E5 00F3 | SLA: 72-hour initial response