Junglewise Threat Intelligence

CVE-2026-87946: Drupal SAML SSO Service Provider weak cryptographic practices

CVE-2026-87946 · Severity: info · Published 2026-09-09

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Miniorange Saml, miniOrange SAML SSO - Service Provider. Vendors: Packagist:Https://Packages.Drupal.Org/8, miniOrange.

Executive brief

The miniOrange SAML SSO Service Provider module for Drupal allows external single sign-on authentication but uses non-standard cryptographic practices that weaken security. The module performs timing-sensitive signature validation using non-constant-time comparison and generates predictable SAML request identifiers, which could reduce the security margin of the authentication system. While no demonstrated authentication bypass exists yet, these weaknesses create potential for future exploits against Drupal sites relying on this module for federated identity authentication.

Technical details

The module implements SAML 2.0 Service Provider functionality with two cryptographic weaknesses: non-constant-time signature comparison logic vulnerable to timing attacks, and predictable SAML request ID generation using non-cryptographic random number generation. Both issues are in the module's core authentication workflow. An attacker with network access could potentially exploit these weaknesses in combination to forge or manipulate SAML requests, though practical authentication bypass has not been documented. The fix is available in version 3.2.0.

Affected products

  • miniOrange SAML SSO - Service Provider before 3.2.0

Timeline

  • 2026-09-09: disclosed

References

Related threats