CVE-2026-46491 | simplesamlphp simplesamlphp-module-casserver up to 7.0.2 SimpleSAMLphp deleteTicket path traversal (GHSA-jrrg-99xh-5j2q)
A vulnerability, which was classified as critical, has been found in simplesamlphp simplesamlphp-module-casserver up to 7.0.2. Affected by this issue is the function deleteTicket of the component SimpleSAMLphp Module. This manipulation causes path traversal.
This vulnerability appears as CVE-2026-46491. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.