PT-2026-89247 · Packagist · Miniorange Drupal Saml Sp

CVE-2026-87948

·

Published

2026-09-09

·

Updated

2026-09-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.
The module does not sufficiently sanitize user-supplied data before displaying it in generated HTML leading to a cross-site scripting vulnerability (XSS).
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-87948
DRUPAL-CONTRIB-2026-146

Affected Products

Miniorange Drupal Saml Sp