Junglewise Threat Intelligence

CVE-2026-5343: Drupal SAML SSO - Service Provider authentication bypass

CVE-2026-5343 · Severity: info · CVSS 9.8 · Published 2026-05-28

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Miniorange Saml. Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

A critical security vulnerability exists in the Drupal SAML SSO - Service Provider module, which is used to allow users to sign into Drupal websites using external identity providers. This flaw allows an attacker to bypass authentication and gain unauthorized access to user accounts, potentially including administrative accounts. This could lead to full site takeover, data theft, or unauthorized modification of website content.

Technical details

The Drupal SAML SSO - Service Provider module fails to sufficiently validate authentication responses, leading to an 'Improper Check for Unusual or Exceptional Conditions' (CWE-754). This vulnerability allows a remote, unauthenticated attacker to bypass the SAML authentication process and log in as any user, including administrators, by exploiting flaws in how the module handles SAML assertions or exceptional conditions during the SSO handshake. The issue affects all versions prior to 3.1.4. Users are advised to upgrade to version 3.1.4 immediately to remediate the risk.

Affected products

  • Drupal SAML SSO - Service Provider >= 0.0.0, < 3.1.4

Timeline

  • 2026-04-01: advisory: Drupal Security Team published SA-CONTRIB-2026-031
  • 2026-05-28: disclosed: CVE-2026-5343 published to NVD
  • 2026-04-01: patched: Version 3.1.4 released to address the vulnerability

References

Related threats