SA-CONTRIB-2026-149: Critical severity drupal/miniorange_saml vulnerability
This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider. The module stores sensitive authentication information in a manner that could allow disclosure to users with access to configuration or related system data. This vulnerability is mitigated by the fact that an attacker must first obtain access to configuration or underlying storage mechanisms.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/miniorange_samlto a version that resolves this vulnerability.Fixed in 3.2.0
Event History
Frequently Asked Questions
Who could realistically exploit this issue?
An attacker would first need access to the site's configuration or to underlying storage mechanisms containing the module's data. This limits exposure to users or attackers who have already obtained that level of access.
What information may be exposed?
The module stores sensitive authentication information in a way that could permit its disclosure to someone with access to configuration or related system data.