CVE-2026-5343: Miniorange SAML SSO - Service Provider

High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation. This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.4.

Affected products

  • Miniorange SAML SSO - Service Provider: from 3.0.1, before 3.1.4 (fixed in 3.1.4); version 7.x-1.0 only; version 7.x-1.1 only; version 7.x-1.2 only; version 7.x-1.3 only; version 7.x-1.4 only; …

Published 2026-05-28. Last modified 2026-07-21.