Preliminary research
The Danger of Multi-SSO AWS Cognito User Pools
AI-collected research leads through 2 October 2026, including bounded month-by-month reviews of selected social and community sources from April through September. Unranked, incomplete, not community-vetted, and subject to change.
AWS Cognito user pools with several SAML providers can expose different validation paths on first and returning logins. The research combines trigger gaps, attacker-controlled federated subject parsing, ghost identities and unverified provider-routing identifiers into account-confusion and takeover scenarios.
Record
- Researcher
- Francesco Lacerenza and Mohamed Ouad
- Published by
- Doyensec
In the archive
Related sources
- Lab Repository
Tags
This page is the archive's own catalogue record. The research is the work of Francesco Lacerenza and Mohamed Ouad, first published at the original source. Preserved copies are kept so the citation survives its host.