Junglewise Threat Intelligence

CVE-2026-87949: SAML SSO Service Provider cross-site scripting in SAML assertion display

CVE-2026-87949 · Severity: info · Published 2026-09-09

Technologies: miniOrange SAML SSO - Service Provider, Packagist:Https://Packages.Drupal.Org/8 Drupal/Miniorange Saml. Vendors: miniOrange, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The miniOrange SAML SSO module for Drupal allows organizations to authenticate users through external identity providers using SAML 2.0. The module fails to properly sanitize values from SAML assertions before displaying them, allowing a malicious identity provider or attacker to inject malicious scripts that execute in users' browsers. This could lead to session hijacking, credential theft, or unauthorized actions on behalf of compromised users.

Technical details

The vulnerability is a reflected/stored cross-site scripting (XSS) flaw in how the miniorange_saml Drupal module handles SAML assertion attributes. An attacker controlling the identity provider or able to intercept and modify SAML responses can inject JavaScript into assertion fields that are rendered without sanitization. The attack requires either compromise of the external IdP or the ability to perform MITM/modify SAML attributes before display to end users.

Affected products

  • miniOrange SAML SSO - Service Provider before 3.2.0

Timeline

  • 2026-09-09: disclosed

References

Related threats