Authentication Bypass Vulnerability in miniOrange SAML SSO by miniOrange
CVE-2026-77998
What is CVE-2026-77998?
The miniOrange SAML SSO plugin contains a vulnerability that allows unauthorized users to bypass authentication. This is facilitated by the mo_saml_validate_signature() function, which improperly assesses a specific return value from PHP's openssl_verify() function. As a result, an attacker can manipulate the SAMLResponse parameter, submitting a crafted request that leads to unintended access to Joomla user accounts, including those of administrators. This flaw underscores the importance of robust validation mechanisms in authentication processes to mitigate the risk of unauthorized access.
Affected Version(s)
SAML SP Single Sign On β Login with ADFS extension for Joomla 1.0.0-6.3.0
SAML SSO for Joomla extension for Joomla 1.0.0-11.0.1
SAML SSO login with Google Apps extension for Joomla 1.0.0-6.3.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
