Known Vulnerabilities for SAML SSO - Service Provider by Drupal
Listed below are 8 of the newest known vulnerabilities associated with "SAML SSO - Service Provider" by "Drupal".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49454 json | Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept forge... | Not Provided | 2026-06-18 | 2026-06-22 |
| CVE-2026-41694 json | Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without req... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-41670 json | Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO modu... | Not Provided | 2026-05-07 | 2026-05-07 |
| CVE-2026-41577 json | authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (... | Not Provided | 2026-06-02 | 2026-06-03 |
| CVE-2026-41005 json | Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signat... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-40988 json | An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vuln... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-9093 json | In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction e... | Not Provided | 2026-05-28 | 2026-06-02 |
| CVE-2026-5343 json | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Esc... | Not Provided | 2026-05-28 | 2026-05-29 |