GHSA-9622-2jm8-94x7 · Severity: high — Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service...
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation. This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.4.
Conclusion & alert: CVE-2026-5343 is rated Low Risk (31.5/100): CVSS High severity, with low exploitation likelihood (EPSS 0.02%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-29 | — | 0.02% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.4 | 3.1 | HIGH |
|
2.2 | 5.2 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-9622-2jm8-94x7 · Severity: high — Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| miniorange | saml_sso_-_service_provider | >= 3.0.1, < 3.1.4 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:*:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.0 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.0:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.1 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.1:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.2 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.2:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.3 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.3:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.4 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.4:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.5 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.5:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.6 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.6:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.7 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.7:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.8 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.8:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.9 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.9:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.91 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.91:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.92 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.92:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.93 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.93:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.94 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.94:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.95 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.95:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.96 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.96:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.97 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.97:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.98 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.98:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.99 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.99:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.991 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.991:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.992 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.992:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.993 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.993:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.994 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.994:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-1.995 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-1.995:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.0 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.0:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.1 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.1:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.2 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.2:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.3 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.3:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.4 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.4:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.5 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.5:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.51 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.51:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.52 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.52:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.53 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.53:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.54 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.54:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.55 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.55:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.56 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.56:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.60 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.60:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.61 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.61:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.70 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.70:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.71 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.71:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 7.x-2.72 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:7.x-2.72:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-1.0 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-1.0:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-1.1 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-1.1:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-1.2 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-1.2:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-1.3 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-1.3:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-1.4 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-1.4:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-1.5 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-1.5:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-1.6 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-1.6:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-1.7 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-1.7:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-1.8 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-1.8:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-1.9 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-1.9:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-1.10 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-1.10:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-1.11 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-1.11:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-1.12 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-1.12:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-1.121 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-1.121:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-1.122 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-1.122:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.0 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.0:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.1 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.1:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.11 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.11:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.12 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.12:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.13 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.13:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.14 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.14:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.15 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.15:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.16 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.16:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.17 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.17:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.18 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.18:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.19 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.19:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.20 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.20:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.21 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.21:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.22 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.22:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.23 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.23:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.24 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.24:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.25 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.25:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.26 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.26:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.27 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.27:*:*:*:*:drupal:*:* |
| miniorange | saml_sso_-_service_provider | 8.x-2.28 | cpe:2.3:a:miniorange:saml_sso_-_service_provider:8.x-2.28:*:*:*:*:drupal:*:* |
| URL | Tags |
|---|---|
| https://www.drupal.org/sa-contrib-2026-031 | Vendor Advisory |