PT-2026-29675 · Drupal+1 · Saml Sso - Service Provider+1
Damien Mckenna
+4
·
Published
2026-04-01
·
Updated
2026-05-28
·
CVE-2026-5343
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal SAML SSO - Service Provider versions 0.0.0 through 3.1.3
Description
This module enables SAML-protocol-based single-sign-on (SSO) on a Drupal site. An improper check for unusual or exceptional conditions allows for an authentication bypass, which can lead to privilege escalation.
Recommendations
Update to version 3.1.4.
Fix
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Saml Sso - Service Provider
Miniorange Drupal Saml Sp