View online: https://www.drupal.org/sa-contrib-2026-141 Project: SAML SSO - Service Provider [1] Date: 2026-September-09 Security risk: *Critical* 18 ∕ 25 AC:None/A:None/CI:Some/II:Some/E:Theoretical/TD:All [2] Vulnerability: Improper access control Affected versions: <3.2.0 CVE IDs: CVE-2026-87943 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider. The miniorange_saml module does not correctly restrict access to certain functionality intended for administrative use. This could allow unauthorized users to access functionality or modify configuration values that should only be available to privileged users. Solution: Install the latest version: * Upgrade to SAML SSO - Service Provider 3.2.0 [3]. Reported By: * Brian Willows (hsjbrianwillows) [4] Fixed By: * Roushan Kumar Singh (roushan59227) [5] * Sudhanshu Dhage (sudhanshu0542) [6] Coordinated By: * Bram Driesen (bramdriesen) [7] of the Drupal Security Team * Greg Knaddison (greggles) [8] of the Drupal Security Team * Juraj Nemec (poker10) [9] of the Drupal Security Team * Jess (xjm) [10] of the Drupal Security Team * Swan Kalata (akalata) [11] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [12] [1] https://www.drupal.org/project/miniorange_saml [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/miniorange_saml/releases/3.2.0 [4] https://www.drupal.org/u/hsjbrianwillows [5] https://www.drupal.org/u/roushan59227 [6] https://www.drupal.org/u/sudhanshu0542 [7] https://www.drupal.org/u/bramdriesen [8] https://www.drupal.org/u/greggles [9] https://www.drupal.org/u/poker10 [10] https://www.drupal.org/u/xjm [11] https://www.drupal.org/u/akalata [12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....