A pre‑authentication bug in SAML Web SSO, combined with weak access controls and cryptography, allows attackers to escalate privileges and achieve remote code execution.
On April 10, 2026, the Department of Justice (DOJ) announced a nearly $17.1 million settlement with IBM to resolve ...