CVE-2026-5343

HIGH EPSS 16.9%
Published May 28, 20261mo ago · Modified Jun 17, 20261w ago
7.4 CVSS 3.1
High
Find Similar
Published May 28, 2026 1mo ago
Last Modified Jun 17, 2026 1w ago

Description

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation. This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.4.

CVSS Details

Base Score
7.4
Exploitability
2.2
Impact
5.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability None

Threat Intelligence

EPSS Exploit Probability
16.9% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-754

Affected Products 77

VendorProductVersionRange
miniorangesaml_sso_-_service_provider*≥3.0.1  –  <3.1.4
miniorangesaml_sso_-_service_provider7.x-1.0any
miniorangesaml_sso_-_service_provider7.x-1.1any
miniorangesaml_sso_-_service_provider7.x-1.2any
miniorangesaml_sso_-_service_provider7.x-1.3any
miniorangesaml_sso_-_service_provider7.x-1.4any
miniorangesaml_sso_-_service_provider7.x-1.5any
miniorangesaml_sso_-_service_provider7.x-1.6any
miniorangesaml_sso_-_service_provider7.x-1.7any
miniorangesaml_sso_-_service_provider7.x-1.8any
miniorangesaml_sso_-_service_provider7.x-1.9any
miniorangesaml_sso_-_service_provider7.x-1.91any
miniorangesaml_sso_-_service_provider7.x-1.92any
miniorangesaml_sso_-_service_provider7.x-1.93any
miniorangesaml_sso_-_service_provider7.x-1.94any
miniorangesaml_sso_-_service_provider7.x-1.95any
miniorangesaml_sso_-_service_provider7.x-1.96any
miniorangesaml_sso_-_service_provider7.x-1.97any
miniorangesaml_sso_-_service_provider7.x-1.98any
miniorangesaml_sso_-_service_provider7.x-1.99any
miniorangesaml_sso_-_service_provider7.x-1.991any
miniorangesaml_sso_-_service_provider7.x-1.992any
miniorangesaml_sso_-_service_provider7.x-1.993any
miniorangesaml_sso_-_service_provider7.x-1.994any
miniorangesaml_sso_-_service_provider7.x-1.995any
miniorangesaml_sso_-_service_provider7.x-2.0any
miniorangesaml_sso_-_service_provider7.x-2.1any
miniorangesaml_sso_-_service_provider7.x-2.2any
miniorangesaml_sso_-_service_provider7.x-2.3any
miniorangesaml_sso_-_service_provider7.x-2.4any
miniorangesaml_sso_-_service_provider7.x-2.5any
miniorangesaml_sso_-_service_provider7.x-2.51any
miniorangesaml_sso_-_service_provider7.x-2.52any
miniorangesaml_sso_-_service_provider7.x-2.53any
miniorangesaml_sso_-_service_provider7.x-2.54any
miniorangesaml_sso_-_service_provider7.x-2.55any
miniorangesaml_sso_-_service_provider7.x-2.56any
miniorangesaml_sso_-_service_provider7.x-2.60any
miniorangesaml_sso_-_service_provider7.x-2.61any
miniorangesaml_sso_-_service_provider7.x-2.70any
miniorangesaml_sso_-_service_provider7.x-2.71any
miniorangesaml_sso_-_service_provider7.x-2.72any
miniorangesaml_sso_-_service_provider8.x-1.0any
miniorangesaml_sso_-_service_provider8.x-1.1any
miniorangesaml_sso_-_service_provider8.x-1.2any
miniorangesaml_sso_-_service_provider8.x-1.3any
miniorangesaml_sso_-_service_provider8.x-1.4any
miniorangesaml_sso_-_service_provider8.x-1.5any
miniorangesaml_sso_-_service_provider8.x-1.6any
miniorangesaml_sso_-_service_provider8.x-1.7any
miniorangesaml_sso_-_service_provider8.x-1.8any
miniorangesaml_sso_-_service_provider8.x-1.9any
miniorangesaml_sso_-_service_provider8.x-1.10any
miniorangesaml_sso_-_service_provider8.x-1.11any
miniorangesaml_sso_-_service_provider8.x-1.12any
miniorangesaml_sso_-_service_provider8.x-1.121any
miniorangesaml_sso_-_service_provider8.x-1.122any
miniorangesaml_sso_-_service_provider8.x-2.0any
miniorangesaml_sso_-_service_provider8.x-2.1any
miniorangesaml_sso_-_service_provider8.x-2.11any
miniorangesaml_sso_-_service_provider8.x-2.12any
miniorangesaml_sso_-_service_provider8.x-2.13any
miniorangesaml_sso_-_service_provider8.x-2.14any
miniorangesaml_sso_-_service_provider8.x-2.15any
miniorangesaml_sso_-_service_provider8.x-2.16any
miniorangesaml_sso_-_service_provider8.x-2.17any
miniorangesaml_sso_-_service_provider8.x-2.18any
miniorangesaml_sso_-_service_provider8.x-2.19any
miniorangesaml_sso_-_service_provider8.x-2.20any
miniorangesaml_sso_-_service_provider8.x-2.21any
miniorangesaml_sso_-_service_provider8.x-2.22any
miniorangesaml_sso_-_service_provider8.x-2.23any
miniorangesaml_sso_-_service_provider8.x-2.24any
miniorangesaml_sso_-_service_provider8.x-2.25any
miniorangesaml_sso_-_service_provider8.x-2.26any
miniorangesaml_sso_-_service_provider8.x-2.27any
miniorangesaml_sso_-_service_provider8.x-2.28any

References 1

  • drupal.org https://www.drupal.org/sa-contrib-2026-031
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.