SugarCRM versions 6.5.18 CE and below suffer from a SAML authentication XML external entity vulnerability.