Junglewise Threat Intelligence

CVE-2026-87943: Drupal miniorange_saml improper access control

CVE-2026-87943 · Severity: info · Published 2026-09-09

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Miniorange Saml. Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The miniorange SAML module for Drupal allows websites to use external identity providers for user authentication. A flaw in the module fails to properly restrict access to administrative functions, allowing unauthorized users to access settings and modify configuration that should only be available to site administrators.

Technical details

The miniorange_saml Drupal module lacks proper access control checks on administrative functionality, permitting unauthorized access and configuration modification. The vulnerability affects all versions before 3.2.0, and has been patched in the fixed version. Attack requires network access only with no additional authentication required to reach the unprotected administrative endpoints.

Affected products

  • Drupal miniorange_saml before 3.2.0

Timeline

  • 2026-09-09: disclosed

References

Related threats