Junglewise Threat Intelligence

CVE-2026-82842: miniorange SAML Single Sign On privilege escalation via account matching

CVE-2026-82842 · Severity: high · CVSS 8.1 · Published 2026-09-20

Vendors: miniOrange.

Executive brief

The SAML Single Sign On WordPress plugin improperly verifies identity linkage during single sign-on authentication, ignoring configured matching criteria and always matching by login name. An attacker with control over an identity provider can assert any login name and gain unauthorized access to any WordPress account, including administrator accounts, without credential verification.

Technical details

The plugin fails to honour the configured criterion for linking incoming SSO identities to WordPress accounts, always resolving by login name regardless of configuration. An attacker controlling the identity provider can assert arbitrary login names to authenticate as any user without ownership verification. This is an authentication bypass allowing unauthenticated privilege escalation when the attacker has IdP control.

Affected products

  • miniorange SAML Single Sign On before 6.0.0

Timeline

  • 2026-09-18: disclosed
  • 2026-09-20: patched: Fixed in version 6.0.0

References