CVE-2022-26493
Last modified
CVE-2022-26493 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnerability. An attacker with access to a HTTP-request intercepting method is able to bypass authentication and authorization by removing the SAML Assertion Signature - impersonating existing users and existing roles, including administrative users/roles. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnerability. An attacker with access to a HTTP-request intercepting method is able to bypass authentication and authorization by removing the SAML Assertion Signature - impersonating existing users and existing roles, including administrative users/roles. This vulnerability is not mitigated by configuring the module to enforce signatures or certificate checks. Xecurify recommends updating miniOrange modules to their most recent versions. This vulnerability is present in paid versions of the miniOrange Drupal SAML SP product affecting Drupal 7, 8, and 9.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Drupal | Saml Sp 2.0 Single Sign On | >= 7.x, <= 7.x-2.57 |
| Drupal | Saml Sp 2.0 Single Sign On | >= 8.x, <= 8.x-2.24 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-26493?
How severe is CVE-2022-26493?
How do I fix CVE-2022-26493?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-26485Removing an XSLT parameter during processing could have lead…8.8
- CVE-2022-26486An unexpected message in the WebGPU IPC framework could lead…9.6
- CVE-2022-26487Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-26488In Python before 3.10.3 on Windows, local users can gain pri…7
- CVE-2022-26490st21nfca_connectivity_event_received in drivers/nfc/st21nfca…7.8
- CVE-2022-26491An issue was discovered in Pidgin before 2.14.9. A remote at…5.9
- CVE-2022-26494An XSS was identified in the Admin Web interface of PrimeKey…4.8
- CVE-2022-26495In nbd-server in nbd before 3.24, there is an integer overfl…9.8
- CVE-2022-26496In nbd-server in nbd before 3.24, there is a stack-based buf…9.8
- CVE-2022-26497BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor c…5.4
- CVE-2022-26498An issue was discovered in Asterisk through 19.x. When using…7.5
- CVE-2022-26499An SSRF issue was discovered in Asterisk through 19.x. When …9.1
Are you affected by CVE-2022-26493?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
