Junglewise Threat Intelligence

CVE-2026-87950: miniOrange SAML Service Provider embedded credentials information disclosure

CVE-2026-87950 · Severity: info · Published 2026-09-09

Technologies: miniOrange SAML SSO - Service Provider, Packagist:Https://Packages.Drupal.Org/8 Drupal/Miniorange Saml. Vendors: miniOrange, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The miniOrange SAML Service Provider module for Drupal allows organizations to configure single sign-on through external identity providers. The module contains embedded credentials that could leak information about associated services under certain circumstances, potentially exposing configuration details about the site's authentication infrastructure.

Technical details

The vulnerability involves hardcoded or insufficiently protected credentials embedded in the module code. An attacker with access to these credentials could potentially enumerate or gather information about connected identity provider services. The issue affects all versions before 3.2.0 and is resolved by upgrading to version 3.2.0 or later.

Affected products

  • miniOrange SAML SSO - Service Provider <3.2.0

Timeline

  • 2026-09-09: disclosed

References

Related threats