Improper access control in SAML SSO - Service Provider - CVE-2026-87943
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the miniorange_saml module does not correctly restrict access to certain functionality intended for administrative use. A remote attacker can access functionality or modify configuration values without proper privileges.