SA-CONTRIB-2026-148: Critical severity drupal/miniorange_saml vulnerability
This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider. The module contains embedded credentials used by the functionality provided by the module. Under certain circumstances, these credentials could allow information about associated services to be disclosed.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/miniorange_samlto a version that resolves this vulnerability.Fixed in 3.2.0 - Operational
Review the embedded credentials used by the Drupal SAML 2.0 Service Provider module functionality and rotate/redeploy them to eliminate any possibility of disclosure of associated services under the described circumstances.
Event History
Frequently Asked Questions
What information could be exposed if these embedded credentials are abused?
The available information only states that information about associated services could be disclosed; it does not identify the specific data types or services.
What conditions are required for exploitation?
The advisory says exploitation is possible only under certain circumstances, but does not specify what those circumstances are or whether attacker authentication is required.