CVE-2026-77998: Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4

Published Aug 25, 2026
·
Updated

Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 - This is due to the mosamlvalidatesignature() function performing a loose boolean check on the raw tri-state integer returned by PHP's opensslverify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification. This makes it possible for unauthenticated attackers to log in as any existing Joomla user, including administrators, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a deliberately malformed signature value that triggers an OpenSSL processing error — bypassing verification entirely and resulting in wpsetauthcookie() being called for the targeted account.

Affected Software

3 affected components
Joomla extension - miniOrange SAML SSO<11.0.2
Joomla extension - SAML SP Single Sign On – Login with ADFS<6.4
Joomla extension - SAML SP Single Sign On – SAML SSO login with Google Apps<6.4

Event History

Aug 25, 2026
CVE Published
via MITRE·12:50 PM
Data Sourced
via MITRE·12:50 PM
DescriptionWeakness
Data Sourced
via NVD·01:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An unauthenticated attacker can exploit it remotely by submitting a crafted SAMLResponse. The attacker needs to target an existing Joomla user account and can impersonate that user, including an administrator.

2

What does an attacker need to send to bypass authentication?

The crafted SAMLResponse must contain an attacker-controlled NameID for the account being targeted and a deliberately malformed signature that causes an OpenSSL processing error. The vulnerable signature-validation logic treats that error as a successful verification.

3

Which extension versions are affected?

Affected versions are miniOrange SAML SSO before 11.0.2, SAML SP Single Sign On – Login with ADFS before 6.4, and SAML SP Single Sign On – SAML SSO login with Google Apps before 6.4.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203