Executive brief
The miniorange SAML module for Drupal allows websites to use external identity providers for user authentication. A flaw in the module fails to properly restrict access to administrative functions, allowing unauthorized users to access settings and modify configuration that should only be available to site administrators.
Technical details
The miniorange_saml Drupal module lacks proper access control checks on administrative functionality, permitting unauthorized access and configuration modification. The vulnerability affects all versions before 3.2.0, and has been patched in the fixed version. Attack requires network access only with no additional authentication required to reach the unprotected administrative endpoints.
Affected products
- Drupal miniorange_saml before 3.2.0
Timeline
- 2026-09-09: disclosed