Junglewise Threat Intelligence

CVE-2026-87947: Drupal miniorange_saml signature algorithm verification bypass

CVE-2026-87947 · Severity: info · Published 2026-09-09

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Miniorange Saml, miniOrange SAML SSO - Service Provider. Vendors: Packagist:Https://Packages.Drupal.Org/8, miniOrange.

Executive brief

The SAML SSO Service Provider module for Drupal allows external identity verification for user authentication. An attacker who can intercept or influence SAML responses can bypass signature validation by selecting the algorithm used to verify assertions, potentially gaining unauthorized access to user accounts or administrative functions. The attack requires the ability to submit a crafted SAML response to the affected Drupal site.

Technical details

The module fails to enforce a fixed signature algorithm for SAML assertion validation, instead allowing the algorithm to be specified in the incoming SAML response. This enables signature algorithm substitution attacks where an attacker crafts a response using a weaker or different algorithm than the IdP's configured key type expects. An attacker capable of submitting a malicious SAML response can exploit this to forge or replay assertions and achieve authentication bypass. The vulnerability is fixed in version 3.2.0.

Affected products

  • miniorange SAML SSO - Service Provider before 3.2.0

Timeline

  • 2026-09-09: disclosed

References

Related threats