Junglewise Threat Intelligence

CVE-2026-87948: Drupal SAML SSO Service Provider cross-site scripting in HTML output

CVE-2026-87948 · Severity: info · Published 2026-09-09

Technologies: miniOrange SAML SSO - Service Provider, Packagist:Https://Packages.Drupal.Org/8 Drupal/Miniorange Saml. Vendors: miniOrange, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The miniOrange SAML SSO Service Provider module enables Drupal sites to authenticate users through external SAML identity providers. The module fails to sanitize user-supplied data before displaying it in HTML, allowing an attacker to inject malicious scripts that execute in other users' browsers and steal session tokens, credentials, or perform unauthorized actions.

Technical details

The vulnerability is a stored or reflected cross-site scripting (XSS) flaw in the SAML SSO Service Provider module for Drupal, caused by insufficient input sanitization when rendering HTML. An authenticated admin user or attacker with data injection capability can supply unsanitized input that gets displayed in generated HTML pages. A fix is available in version 3.2.0 and later.

Affected products

  • miniOrange SAML SSO - Service Provider before 3.2.0

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Version 3.2.0 released

References

Related threats