SA-CONTRIB-2026-141: Critical severity drupal/miniorange_saml vulnerability
This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider. The miniorangesaml module does not correctly restrict access to certain functionality intended for administrative use. This could allow unauthorized users to access functionality or modify configuration values that should only be available to privileged users.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/miniorange_samlto a version that resolves this vulnerability.Fixed in 3.2.0
Event History
Frequently Asked Questions
Who could exploit this issue?
Unauthorized users may be able to access administrative functionality or change configuration values that should be restricted to privileged users. The provided information does not specify whether authentication, a particular role, or any other precondition is required.
What systems are affected?
The issue affects the Drupal miniorange_saml module, which configures a Drupal site as a SAML 2.0 Service Provider. No affected or fixed module versions are provided.
How can administrators determine whether they are exposed?
Review the miniorange_saml module's administrative functions and configuration paths to confirm that only privileged users can access them or modify their values. The advisory does not identify the specific functionality, routes, or permissions involved.