Junglewise Threat Intelligence

CVE-2026-62108: Headless Single Sign On broken authentication bypass

CVE-2026-62108 · Severity: critical · CVSS 9.8 · Published 2026-09-17

Vendors: miniOrange.

Executive brief

Headless Single Sign On is a WordPress plugin that manages user authentication and login for websites. Versions 1.7.0 and earlier contain a critical authentication flaw that allows attackers to bypass the login system entirely and log in as any user without a password. This vulnerability has a CVSS score of 9.8 and could lead to complete account takeover and unauthorized access to sensitive website functions and customer data.

Technical details

This is a broken authentication vulnerability (OWASP A7) in the Headless Single Sign On WordPress plugin versions 1.7.0 and earlier. The vulnerability allows unauthenticated attackers to bypass the plugin's login mechanism and gain access as arbitrary users without requiring valid credentials. No special privileges or user interaction are required for exploitation; the attack is network-accessible and can be performed by any remote attacker. The flaw has been patched in version 1.7.1. Patchstack has released a mitigation rule to block attacks against unpatched installations.

Affected products

  • miniOrange Headless Single Sign On <= 1.7.0

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Version 1.7.1 released

References