Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-77998: miniOrange SAML login lets attackers log in as any user

CVE-2026-77998 · published 9 days ago
Summary

The miniOrange SAML Single Sign-On extensions for Joomla (versions before 11.0.2 and 6.4) do not correctly check the digital signature on login messages. Because of this, a stranger can send a specially crafted login request and be accepted as any existing Joomla account, even an administrator. Update the extensions to the latest versions or disable the SAML SSO feature until the fix is applied.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
miniorange.com saml sso for joomla extension for joomla 1.0.0-11.0.1
miniorange.com saml sp single sign on – login with adfs extension for joomla 1.0.0-6.3.0
miniorange.com saml sso login with google apps extension for joomla 1.0.0-6.3.0
miniorange.com saml sso free for joomla extension for joomla 1.0.0-11.0.1
miniorange.com saml sso basic for joomla extension for joomla 1.0.0-13.1.0
miniorange.com saml sso standard for joomla extension for joomla 1.0.0-24.1.0
miniorange.com saml sso premium for joomla extension for joomla 1.0.0-34.1.0
miniorange.com saml sso enterprise for joomla extension for joomla 1.0.0-44.1.0
miniorange.com oauth single sign-on – oidc sso | login with azure ad 1.0.0-1.2.1
miniorange.com login with keycloak oauth single sign-on (sso) 1.0.0-1.2.1
miniorange.com single sign-on for educational institutes - version 1.0.0-1.2.1
Original advisory text
Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4
Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 - This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification. This makes it possible for unauthenticated attackers to log in as any existing Joomla user, including administrators, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a deliberately malformed signature value that triggers an OpenSSL processing error — bypassing verification entirely and resulting in wp_set_auth_cookie() being called for the targeted account.
Severity
10.0 Critical
CVSS 4.0: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published25 Aug 2026
Updated30 Aug 2026
First seen25 Aug 2026
Sources
CVE-2026-77998 · MITRE
Monitor software like this
Free during beta