Junglewise Threat Intelligence

CVE-2026-87944: Drupal SAML SSO Service Provider TLS certificate validation bypass

CVE-2026-87944 · Severity: info · Published 2026-09-09

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Miniorange Saml. Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The SAML SSO - Service Provider module for Drupal allows websites to authenticate users through external identity providers. The module fails to properly validate TLS certificates when communicating with these external services, allowing an attacker who intercepts network traffic to impersonate the identity provider and influence authentication communications. Successful exploitation could lead to unauthorized user account creation, session hijacking, or account takeover.

Technical details

The vulnerability is an improper certificate validation flaw (CWE-295) in outbound HTTPS requests made by the module. An attacker positioned to intercept or redirect network traffic can perform a man-in-the-middle attack without needing the identity provider's private key. The vulnerability affects all versions before 3.2.0 and is fixed in that version.

Affected products

  • Drupal SAML SSO - Service Provider (miniorange_saml) < 3.2.0

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Fixed in version 3.2.0

References

Related threats