CVE-2026-77998 | MiniOrange SAML SSO Extension up to 11.0.1 SAML Signature Verification mo_saml_validate_signature SAMLResponse improper authentication (EUVD-2026-65476)
A vulnerability, which was classified as critical, has been found in MiniOrange SAML SSO Extension up to 11.0.1. The impacted element is the function mo_saml_validate_signature of the component SAML Signature Verification. The manipulation of the argument SAMLResponse leads to improper authentication.
This vulnerability is traded as CVE-2026-77998. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More