CVE-2026-5343
Analyzed
Analyzed - Analysis Complete
Privilege Escalation in Drupal SAML SSO Service Provider
Publication date: 2026-05-28
Last updated on: 2026-06-01
Assigner: Drupal.org
Description
Description
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation.
This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.4.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| miniorange | saml_sso_-_service_provider | 7.x-1.0 |
| miniorange | saml_sso_-_service_provider | 7.x-1.1 |
| miniorange | saml_sso_-_service_provider | 7.x-1.2 |
| miniorange | saml_sso_-_service_provider | 7.x-1.3 |
| miniorange | saml_sso_-_service_provider | 7.x-1.4 |
| miniorange | saml_sso_-_service_provider | 7.x-1.5 |
| miniorange | saml_sso_-_service_provider | 7.x-1.6 |
| miniorange | saml_sso_-_service_provider | 7.x-1.7 |
| miniorange | saml_sso_-_service_provider | 7.x-1.8 |
| miniorange | saml_sso_-_service_provider | 7.x-1.9 |
| miniorange | saml_sso_-_service_provider | 7.x-1.91 |
| miniorange | saml_sso_-_service_provider | 7.x-1.92 |
| miniorange | saml_sso_-_service_provider | 7.x-1.93 |
| miniorange | saml_sso_-_service_provider | 7.x-1.94 |
| miniorange | saml_sso_-_service_provider | 7.x-1.95 |
| miniorange | saml_sso_-_service_provider | 7.x-1.96 |
| miniorange | saml_sso_-_service_provider | 7.x-1.97 |
| miniorange | saml_sso_-_service_provider | 7.x-1.98 |
| miniorange | saml_sso_-_service_provider | 7.x-1.99 |
| miniorange | saml_sso_-_service_provider | 7.x-1.991 |
| miniorange | saml_sso_-_service_provider | 7.x-1.992 |
| miniorange | saml_sso_-_service_provider | 7.x-1.993 |
| miniorange | saml_sso_-_service_provider | 7.x-1.994 |
| miniorange | saml_sso_-_service_provider | 7.x-1.995 |
| miniorange | saml_sso_-_service_provider | 7.x-2.0 |
| miniorange | saml_sso_-_service_provider | 7.x-2.1 |
| miniorange | saml_sso_-_service_provider | 7.x-2.2 |
| miniorange | saml_sso_-_service_provider | 7.x-2.3 |
| miniorange | saml_sso_-_service_provider | 7.x-2.4 |
| miniorange | saml_sso_-_service_provider | 7.x-2.5 |
| miniorange | saml_sso_-_service_provider | 7.x-2.51 |
| miniorange | saml_sso_-_service_provider | 7.x-2.52 |
| miniorange | saml_sso_-_service_provider | 7.x-2.53 |
| miniorange | saml_sso_-_service_provider | 7.x-2.54 |
| miniorange | saml_sso_-_service_provider | 7.x-2.55 |
| miniorange | saml_sso_-_service_provider | 7.x-2.56 |
| miniorange | saml_sso_-_service_provider | 7.x-2.60 |
| miniorange | saml_sso_-_service_provider | 7.x-2.61 |
| miniorange | saml_sso_-_service_provider | 7.x-2.70 |
| miniorange | saml_sso_-_service_provider | 7.x-2.71 |
| miniorange | saml_sso_-_service_provider | 7.x-2.72 |
| miniorange | saml_sso_-_service_provider | 8.x-1.0 |
| miniorange | saml_sso_-_service_provider | 8.x-1.1 |
| miniorange | saml_sso_-_service_provider | 8.x-1.10 |
| miniorange | saml_sso_-_service_provider | 8.x-1.11 |
| miniorange | saml_sso_-_service_provider | 8.x-1.12 |
| miniorange | saml_sso_-_service_provider | 8.x-1.121 |
| miniorange | saml_sso_-_service_provider | 8.x-1.122 |
| miniorange | saml_sso_-_service_provider | 8.x-1.2 |
| miniorange | saml_sso_-_service_provider | 8.x-1.3 |
| miniorange | saml_sso_-_service_provider | 8.x-1.4 |
| miniorange | saml_sso_-_service_provider | 8.x-1.5 |
| miniorange | saml_sso_-_service_provider | 8.x-1.6 |
| miniorange | saml_sso_-_service_provider | 8.x-1.7 |
| miniorange | saml_sso_-_service_provider | 8.x-1.8 |
| miniorange | saml_sso_-_service_provider | 8.x-1.9 |
| miniorange | saml_sso_-_service_provider | 8.x-2.0 |
| miniorange | saml_sso_-_service_provider | 8.x-2.1 |
| miniorange | saml_sso_-_service_provider | 8.x-2.11 |
| miniorange | saml_sso_-_service_provider | 8.x-2.12 |
| miniorange | saml_sso_-_service_provider | 8.x-2.13 |
| miniorange | saml_sso_-_service_provider | 8.x-2.14 |
| miniorange | saml_sso_-_service_provider | 8.x-2.15 |
| miniorange | saml_sso_-_service_provider | 8.x-2.16 |
| miniorange | saml_sso_-_service_provider | 8.x-2.17 |
| miniorange | saml_sso_-_service_provider | 8.x-2.18 |
| miniorange | saml_sso_-_service_provider | 8.x-2.19 |
| miniorange | saml_sso_-_service_provider | 8.x-2.20 |
| miniorange | saml_sso_-_service_provider | 8.x-2.21 |
| miniorange | saml_sso_-_service_provider | 8.x-2.22 |
| miniorange | saml_sso_-_service_provider | 8.x-2.23 |
| miniorange | saml_sso_-_service_provider | 8.x-2.24 |
| miniorange | saml_sso_-_service_provider | 8.x-2.25 |
| miniorange | saml_sso_-_service_provider | 8.x-2.26 |
| miniorange | saml_sso_-_service_provider | 8.x-2.27 |
| miniorange | saml_sso_-_service_provider | 8.x-2.28 |
| miniorange | saml_sso_-_service_provider | From 3.0.1 (inc) to 3.1.4 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-754 | The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product. |