it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Authentication bypass - SA-CONTRIB-2026-145
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Authentication bypass - SA-CONTRIB-2026-145
- Date: Wed, 9 Sep 2026 17:21:28 +0000
- Arc-authentication-results: i=2; smtp3.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
- Arc-authentication-results: i=1; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=p5P2B8UX; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=eu6p6dCW; arc=none smtp.remote-ip=54.240.27.123
- Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org DB6636FE6A
- Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org 25D83407AE
- Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788976622; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=7plujn/bfq5E0vmILbfENiI41UonwmMqsX7l57UzLpk=; b=bI9Axzrnb3vAQEzgcvXmD+Mbu+AWTS3g5v3ZKaiTUL75LGS5y26otWTxwsO0X90I4PVl YqxHZajpFZJKgMvRkNxQe+YU6/tV2zouHCP79rIDe0KRMQN0OTWwOFVkdI9lEtGeXRmk4 4jP2Rn7yy2bbFpqVRiMqxf9x6+cXJBS4EQ0kthgx7hjt0/8PfnM2jR6fs0o+7TOMP+70j F+g2E6i1nTTsMnKnEKQ9Vyhxrh9JAIIJUi1JLKoICvM0Ds5xX33M830bIs4FOkXtrJCur 9kQW500pj2zzQpCJB+rcO7vXHtVrGcdT3BC+biMsRefD/n/erLxj9ExYdwu7sNki0zA==
- Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788974489; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=aRzQ6cXtwEf+eZZkBEjXZSBJIqZcZRUUelCbZvK2sHM=; b=hWIBfy8cmAre6mJmjgyTsIPv8MHstIEG06tUSgzQOHzKDRDCPtTZUgWyfOQtqOXtwIE9 V8Cgugl4hjn1tBp/30DAYKMB6787Vb/Mry0f6CufSvwtbEIm5JULRDuxN+JHtKaxS63TS eVCN9fen1vXsOLnx2AbIvClSGyq4cQJV4QY/Ha9GiXnmqEGtng6nCkZ5UWrIsXeTk1kIa CAuD53OgjZGRT33elmVK+k1Hf7SgDEO2fyy9FKA+qWL/FNr+R8auEOl2OdgXcT99EzvtN 7qHX4fHenGA7A0daIASB24sJwT9U73MC9Zox4LHoAVF7xPmnsDPxtrNZRbqg2zJwXfg==
- Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788976622; b=L5gbmFsEMF5EH70g+uG9tieW4fZzx/zlLSyWbDXfmizDu4WPEoLDPcAh3o+VFOaAugEY F/2FeLXRxT6QOVXT79HU/AslrcEhjimd1cYPQek/7YRqgsYSwh9TMkKzgdn2W10WxgnfX M+u7IEKkvs4PevWpoInUU6iRaCl+0t/Ta06l9gzh/XNidSc5b7+8u4+crdkF6GcLsaPy6 I0nWrEHChAwIlK9wJ7JDXlCIeIttia+c8j2R4+/jV6ETLycRKhA2r65IVFL8FRqxfP9su +vh+wfHMHNCPwqDECTuM1zkXw10ERL4BeafHyEYWX4gQdudiFSGe9Cq2VrcGUibAFdw==
- Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788974489; b=e7Jrs3n3FSFEaW9Z/SUbSS8fzCfqmnc0Ioq7BxofjIL87XWfCHIrJjeJMHbSRzGwk+YT LiaHgkFViu8OvTImzFCIap6iuyL/b/Zd03pjK2vgxFLxcPPXn2vUo2qyIliVjSHKu2SBy FzobKu1dXDpr60jP4Z5rx+rnBWq+9kMCltXpnR5DLmQ6IvTF/MEmIy/bj8pq4ofReVP+x eyEcqfn5NQFAlD1w9zHTlzdNbVyCwu9kZQwzmtW4xsdNawLgct/DzUtQI+p1kAkprfJMl IG01O9JlNpN7gMaHHG7uQ5IB25U0SmWpNT0Uu2IPPICnLVY7HJgCyo3Eh1atKhi1icw==
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/JZGWC3HTQCIACH76MCQKGLZCXO3TL3F3/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=JOFTJ2KY; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=p5P2B8UX; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=eu6p6dCW; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.136 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-145
Project: SAML SSO - Service Provider [1]
Date: 2026-September-09
Security risk: *Moderately critical* 14 ∕ 25
AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Authentication bypass
Affected versions: <3.2.0
CVE IDs: CVE-2026-87947
Description:
This module allows you to configure your Drupal site as a SAML 2.0 Service
Provider so that users can authenticate through an external identity
provider.
The module does not properly restrict which signature algorithm may be used
to validate a SAML assertion, allowing the algorithm to be influenced by the
incoming response rather than being tied to the type of key configured for
the Identity Provider (IdP).
The vulnerability is mitigated by the fact that an attacker must be able to
submit a crafted SAML response to the affected site.
Solution:
Install the latest version:
* Upgrade to SAML SSO - Service Provider 3.2.0 [3].
Reported By:
* Timo De Clercq (timodc) [4]
Fixed By:
* Roushan Kumar Singh (roushan59227) [5]
* Sudhanshu Dhage (sudhanshu0542) [6]
Coordinated By:
* Bram Driesen (bramdriesen) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Heine Deelstra (heine) [9] of the Drupal Security Team
* Juraj Nemec (poker10) [10] of the Drupal Security Team
* Jess (xjm) [11] of the Drupal Security Team
* Swan Kalata (akalata) [12] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [13]
[1] https://www.drupal.org/project/miniorange_saml
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/miniorange_saml/releases/3.2.0
[4] https://www.drupal.org/u/timodc
[5] https://www.drupal.org/u/roushan59227
[6] https://www.drupal.org/u/sudhanshu0542
[7] https://www.drupal.org/u/bramdriesen
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/heine
[10] https://www.drupal.org/u/poker10
[11] https://www.drupal.org/u/xjm
[12] https://www.drupal.org/u/akalata
[13] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3613356
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Authentication bypass - SA-CONTRIB-2026-145, security-news, 09.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.