Web Hack List

Preliminary research

The Danger of Multi-SSO AWS Cognito User Pools

AI-collected research leads through 2 October 2026, including bounded month-by-month reviews of selected social and community sources from April through September. Unranked, incomplete, not community-vetted, and subject to change.

AWS Cognito user pools with several SAML providers can expose different validation paths on first and returning logins. The research combines trigger gaps, attacker-controlled federated subject parsing, ghost identities and unverified provider-routing identifiers into account-confusion and takeover scenarios.

Record

Researcher
Francesco Lacerenza and Mohamed Ouad
Published by
Doyensec

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Francesco Lacerenza and Mohamed Ouad, first published at the original source. Preserved copies are kept so the citation survives its host.