Executive brief
The SAML SSO - Service Provider module for Drupal allows websites to authenticate users through external identity providers. The module fails to properly validate TLS certificates when communicating with these external services, allowing an attacker who intercepts network traffic to impersonate the identity provider and influence authentication communications. Successful exploitation could lead to unauthorized user account creation, session hijacking, or account takeover.
Technical details
The vulnerability is an improper certificate validation flaw (CWE-295) in outbound HTTPS requests made by the module. An attacker positioned to intercept or redirect network traffic can perform a man-in-the-middle attack without needing the identity provider's private key. The vulnerability affects all versions before 3.2.0 and is fixed in that version.
Affected products
- Drupal SAML SSO - Service Provider (miniorange_saml) < 3.2.0
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Fixed in version 3.2.0