Executive brief
miniOrange SAML SSO is a Joomla extension that handles single sign-on authentication. A vulnerability in signature verification logic allows unauthenticated attackers to forge authentication tokens and log in as any user, including administrators, without valid credentials. This can result in complete compromise of Joomla installations relying on this extension for access control.
Technical details
The vulnerability exists in the mo_saml_validate_signature() function, which performs a loose boolean check on the return value of PHP's openssl_verify(). The function fails to properly distinguish between signature verification failure (-1), invalid signature (0), and successful verification (1), treating the error value -1 as truthy and accepting it as valid verification. An unauthenticated attacker can craft a malicious SAMLResponse with an attacker-controlled NameID and a deliberately malformed signature that triggers an OpenSSL error, causing the validation to pass and resulting in authentication as the target user. The attack vector is network-based and requires no prior authentication or user interaction beyond submitting the crafted SAML response.
Affected products
- miniOrange SAML SSO < 11.0.2
- miniOrange SAML SP Single Sign On – Login with ADFS < 6.4
- miniOrange SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4
Timeline
- 2026-08-25: disclosed