Junglewise Threat Intelligence

CVE-2026-87945: Drupal miniorange_saml open redirect in URL validation

CVE-2026-87945 · Severity: info · Published 2026-09-09

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Miniorange Saml, miniOrange SAML SSO - Service Provider. Vendors: Packagist:Https://Packages.Drupal.Org/8, miniOrange.

Executive brief

The miniorange_saml module for Drupal allows organizations to configure single sign-on using SAML 2.0 authentication. A flaw in URL validation allows attackers to redirect authenticated users to external websites, enabling phishing attacks or distributing malicious content with false credibility.

Technical details

The miniorange_saml module fails to sufficiently validate user-supplied URLs before performing post-authentication redirects, enabling an open redirect attack. An unauthenticated attacker can craft URLs to redirect users to external malicious sites after they complete SAML authentication. This vulnerability affects all versions before 3.2.0 and is fixed in version 3.2.0 and later.

Affected products

  • miniOrange SAML SSO - Service Provider before 3.2.0

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Fixed in version 3.2.0

References

Related threats