Intel

AIKIDO-2026-10473

drupal/miniorange_saml is vulnerable to Authentication Bypass

Authentication BypassCVE-2026-5343

95

Critical Risk

This Affects:

PHPdrupal/miniorange_saml
0.0.1 - 3.1.3
Fixed in 3.1.4

TL;DR

This module does not sufficiently block access, leading to a authentication bypass vulnerability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/miniorange_saml is vulnerable to Authentication Bypass in versions 0.0.1 - 3.1.3.

How to fix this

Upgrade the drupal/miniorange_saml library to the patch version.