SAML SSO - Service Provider - Moderately critical - Embedded credentials - SA-CONTRIB-2026-148
View online: https://www.drupal.org/sa-contrib-2026-148 Project: SAML SSO - Service Provider [1] Date: 2026-September-09 Security risk: *Moderately critical* 13 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:Uncommon [2] Vulnerability: Embedded credentials Affected versions: <3.2.0 CVE IDs: CVE-2026-87950 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider. The module contains embedded credentials used by the functionality provided by the module. Under certain circumstances, these credentials could allow information about associated services to be disclosed. Solution: Install the latest version: * Upgrade to miniorange_saml 3.2.0 [3]. Reported By: * Sudhanshu Dhage (sudhanshu0542) [4] Fixed By: * Roushan Kumar Singh (roushan59227) [5] * Sudhanshu Dhage (sudhanshu0542) [6] Coordinated By: * Bram Driesen (bramdriesen) [7] of the Drupal Security Team * Greg Knaddison (greggles) [8] of the Drupal Security Team * Juraj Nemec (poker10) [9] of the Drupal Security Team * Jess (xjm) [10] of the Drupal Security Team * Swan Kalata (akalata) [11] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [12] [1] https://www.drupal.org/project/miniorange_saml [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/miniorange_saml/releases/3.2.0 [4] https://www.drupal.org/u/sudhanshu0542 [5] https://www.drupal.org/u/roushan59227 [6] https://www.drupal.org/u/sudhanshu0542 [7] https://www.drupal.org/u/bramdriesen [8] https://www.drupal.org/u/greggles [9] https://www.drupal.org/u/poker10 [10] https://www.drupal.org/u/xjm [11] https://www.drupal.org/u/akalata [12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org