SA-CONTRIB-2026-143: Critical severity drupal/miniorange_saml vulnerability
This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider. The miniorangesaml module does not sufficiently validate certain user-supplied URLs before performing redirects. An attacker could cause users to be redirected to an external website after authentication. This could be used in phishing attacks or to increase the credibility of malicious links.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/miniorange_samlto a version that resolves this vulnerability.Fixed in 3.2.0
Event History
Frequently Asked Questions
Who is exposed to this issue?
Drupal sites using the miniorange_saml module as a SAML 2.0 Service Provider are affected by the described redirect-validation weakness.
What does an attacker need to exploit it?
An attacker needs to supply a URL that the module does not sufficiently validate, causing a user to be redirected to an external website after authentication.
What is the likely impact of successful exploitation?
The issue can support phishing attacks by redirecting authenticated users to an attacker-controlled external site and making malicious links appear more credible.