CVE-2026-5343: Miniorange SAML SSO - Service Provider
High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation. This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.4.
Affected products
- Miniorange SAML SSO - Service Provider: from 3.0.1, before 3.1.4 (fixed in 3.1.4); version 7.x-1.0 only; version 7.x-1.1 only; version 7.x-1.2 only; version 7.x-1.3 only; version 7.x-1.4 only; …
Published 2026-05-28. Last modified 2026-07-21.