Affected versions: ≥ 1.0.0 and < 11.0.2
Full advisory: our disclosure post
miniOrange SAML SSO for Joomla is affected by an unauthenticated authentication bypass, CVE-2026-77998, scored CVSS 4.0 10.0 (critical). UtilitiesSAML::validateSignature() performs a loose boolean check on the tri-state integer returned by PHP openssl_verify(), so the error return value of -1 is treated as truthy and therefore as a successful signature verification. An unauthenticated attacker can submit a crafted SAMLResponse holding an attacker-controlled NameID together with a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely and logging in as any existing user, administrators included. FIXED VERSIONS: miniOrange ships this extension as several separately numbered editions, and the leading digit identifies the EDITION rather than the age, so a higher version number is not necessarily newer. Free edition is fixed in 11.0.2 (and 6.4 for the ADFS and Google Apps editions). The paid SAML SP editions were announced to miniOrange customers on 26 August 2026 and confirmed publicly the same day by David Jardin of the Joomla Security Strike Team: Basic is affected up to 13.1 and fixed in 13.2; Standard is affected up to 24.1 and fixed in 24.2; Premium is affected up to 34.1 and fixed in 34.2; Enterprise is affected up to 44.1 and fixed in 44.2. UPDATE PATH WARNING: miniOrange state that 13.0, 13.1, 24.0, 24.1, 34.0, 34.1, 44.0 and 44.1 can install the fixed release directly over the top, but anything below 13.0, 24.0, 34.0 or 44.0 must be uninstalled first and then reinstalled. On a site where SAML is the only login method, uninstalling the plugin locks every user out, administrators included, so confirm you have a working local Joomla Super User account and a current backup before you start. If the plugin was customised for you, save its configuration and tell miniOrange before replacing it. NOTE ON THE CVE RECORD: as at 26 August 2026 the published CVE record still gives its affected range as 1.0.0 to 11.0.1, which describes the free edition only, and it has not been re-scoped to cover the paid editions. This rule set deliberately goes beyond the range stated in the CVE, on the strength of the vendor written statement of the paid fix versions. If you cannot update immediately, disable or remove the extension rather than leaving an anonymous administrator login available.
Affected versions: ≥ 1.0.0 and < 11.0.2
Official record: cve.org · NVD
Every connected Joomla site is checked against these rules on each audit, and flagged if it runs an affected version.
Affected versions: ≥ 1.0.0 and < 11.0.2
Full advisory: our disclosure post
miniOrange SAML SSO - miniOrange SAML SSO (com_miniorange_saml) - Unauthenticated Authentication Bypass (CVSS 10.0)
miniOrange SAML SSO for Joomla is affected by an unauthenticated authentication bypass, CVE-2026-77998, scored CVSS 4.0 10.0 (critical). UtilitiesSAML::validateSignature() performs a loose boolean check on the tri-state integer returned by PHP openssl_verify(), so the error return value of -1 is treated as truthy and therefore as a successful signature verification. An unauthenticated attacker can submit a crafted SAMLResponse holding an attacker-controlled NameID together with a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely and logging in as any existing user, administrators included. FIXED VERSIONS: miniOrange ships this extension as several separately numbered editions, and the leading digit identifies the EDITION rather than the age, so a higher version number is not necessarily newer. Free edition is fixed in 11.0.2 (and 6.4 for the ADFS and Google Apps editions). The paid SAML SP editions were announced to miniOrange customers on 26 August 2026 and confirmed publicly the same day by David Jardin of the Joomla Security Strike Team: Basic is affected up to 13.1 and fixed in 13.2; Standard is affected up to 24.1 and fixed in 24.2; Premium is affected up to 34.1 and fixed in 34.2; Enterprise is affected up to 44.1 and fixed in 44.2. UPDATE PATH WARNING: miniOrange state that 13.0, 13.1, 24.0, 24.1, 34.0, 34.1, 44.0 and 44.1 can install the fixed release directly over the top, but anything below 13.0, 24.0, 34.0 or 44.0 must be uninstalled first and then reinstalled. On a site where SAML is the only login method, uninstalling the plugin locks every user out, administrators included, so confirm you have a working local Joomla Super User account and a current backup before you start. If the plugin was customised for you, save its configuration and tell miniOrange before replacing it. NOTE ON THE CVE RECORD: as at 26 August 2026 the published CVE record still gives its affected range as 1.0.0 to 11.0.1, which describes the free edition only, and it has not been re-scoped to cover the paid editions. This rule set deliberately goes beyond the range stated in the CVE, on the strength of the vendor written statement of the paid fix versions. If you cannot update immediately, disable or remove the extension rather than leaving an anonymous administrator login available.
Affected versions: ≥ 11.0.3 and < 13.2
Full advisory: our disclosure post
miniOrange SAML SSO - miniOrange SAML SSO (com_miniorange_saml) - Unauthenticated Authentication Bypass (CVSS 10.0)
miniOrange SAML SSO for Joomla is affected by an unauthenticated authentication bypass, CVE-2026-77998, scored CVSS 4.0 10.0 (critical). UtilitiesSAML::validateSignature() performs a loose boolean check on the tri-state integer returned by PHP openssl_verify(), so the error return value of -1 is treated as truthy and therefore as a successful signature verification. An unauthenticated attacker can submit a crafted SAMLResponse holding an attacker-controlled NameID together with a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely and logging in as any existing user, administrators included. FIXED VERSIONS: miniOrange ships this extension as several separately numbered editions, and the leading digit identifies the EDITION rather than the age, so a higher version number is not necessarily newer. Free edition is fixed in 11.0.2 (and 6.4 for the ADFS and Google Apps editions). The paid SAML SP editions were announced to miniOrange customers on 26 August 2026 and confirmed publicly the same day by David Jardin of the Joomla Security Strike Team: Basic is affected up to 13.1 and fixed in 13.2; Standard is affected up to 24.1 and fixed in 24.2; Premium is affected up to 34.1 and fixed in 34.2; Enterprise is affected up to 44.1 and fixed in 44.2. UPDATE PATH WARNING: miniOrange state that 13.0, 13.1, 24.0, 24.1, 34.0, 34.1, 44.0 and 44.1 can install the fixed release directly over the top, but anything below 13.0, 24.0, 34.0 or 44.0 must be uninstalled first and then reinstalled. On a site where SAML is the only login method, uninstalling the plugin locks every user out, administrators included, so confirm you have a working local Joomla Super User account and a current backup before you start. If the plugin was customised for you, save its configuration and tell miniOrange before replacing it. NOTE ON THE CVE RECORD: as at 26 August 2026 the published CVE record still gives its affected range as 1.0.0 to 11.0.1, which describes the free edition only, and it has not been re-scoped to cover the paid editions. This rule set deliberately goes beyond the range stated in the CVE, on the strength of the vendor written statement of the paid fix versions. If you cannot update immediately, disable or remove the extension rather than leaving an anonymous administrator login available.
Affected versions: ≥ 20.0 and < 24.2
Full advisory: our disclosure post
miniOrange SAML SSO - miniOrange SAML SSO (com_miniorange_saml) - Unauthenticated Authentication Bypass (CVSS 10.0)
miniOrange SAML SSO for Joomla is affected by an unauthenticated authentication bypass, CVE-2026-77998, scored CVSS 4.0 10.0 (critical). UtilitiesSAML::validateSignature() performs a loose boolean check on the tri-state integer returned by PHP openssl_verify(), so the error return value of -1 is treated as truthy and therefore as a successful signature verification. An unauthenticated attacker can submit a crafted SAMLResponse holding an attacker-controlled NameID together with a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely and logging in as any existing user, administrators included. FIXED VERSIONS: miniOrange ships this extension as several separately numbered editions, and the leading digit identifies the EDITION rather than the age, so a higher version number is not necessarily newer. Free edition is fixed in 11.0.2 (and 6.4 for the ADFS and Google Apps editions). The paid SAML SP editions were announced to miniOrange customers on 26 August 2026 and confirmed publicly the same day by David Jardin of the Joomla Security Strike Team: Basic is affected up to 13.1 and fixed in 13.2; Standard is affected up to 24.1 and fixed in 24.2; Premium is affected up to 34.1 and fixed in 34.2; Enterprise is affected up to 44.1 and fixed in 44.2. UPDATE PATH WARNING: miniOrange state that 13.0, 13.1, 24.0, 24.1, 34.0, 34.1, 44.0 and 44.1 can install the fixed release directly over the top, but anything below 13.0, 24.0, 34.0 or 44.0 must be uninstalled first and then reinstalled. On a site where SAML is the only login method, uninstalling the plugin locks every user out, administrators included, so confirm you have a working local Joomla Super User account and a current backup before you start. If the plugin was customised for you, save its configuration and tell miniOrange before replacing it. NOTE ON THE CVE RECORD: as at 26 August 2026 the published CVE record still gives its affected range as 1.0.0 to 11.0.1, which describes the free edition only, and it has not been re-scoped to cover the paid editions. This rule set deliberately goes beyond the range stated in the CVE, on the strength of the vendor written statement of the paid fix versions. If you cannot update immediately, disable or remove the extension rather than leaving an anonymous administrator login available.
Affected versions: ≥ 30.0 and < 34.2
Full advisory: our disclosure post
miniOrange SAML SSO - miniOrange SAML SSO (com_miniorange_saml) - Unauthenticated Authentication Bypass (CVSS 10.0)
miniOrange SAML SSO for Joomla is affected by an unauthenticated authentication bypass, CVE-2026-77998, scored CVSS 4.0 10.0 (critical). UtilitiesSAML::validateSignature() performs a loose boolean check on the tri-state integer returned by PHP openssl_verify(), so the error return value of -1 is treated as truthy and therefore as a successful signature verification. An unauthenticated attacker can submit a crafted SAMLResponse holding an attacker-controlled NameID together with a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely and logging in as any existing user, administrators included. FIXED VERSIONS: miniOrange ships this extension as several separately numbered editions, and the leading digit identifies the EDITION rather than the age, so a higher version number is not necessarily newer. Free edition is fixed in 11.0.2 (and 6.4 for the ADFS and Google Apps editions). The paid SAML SP editions were announced to miniOrange customers on 26 August 2026 and confirmed publicly the same day by David Jardin of the Joomla Security Strike Team: Basic is affected up to 13.1 and fixed in 13.2; Standard is affected up to 24.1 and fixed in 24.2; Premium is affected up to 34.1 and fixed in 34.2; Enterprise is affected up to 44.1 and fixed in 44.2. UPDATE PATH WARNING: miniOrange state that 13.0, 13.1, 24.0, 24.1, 34.0, 34.1, 44.0 and 44.1 can install the fixed release directly over the top, but anything below 13.0, 24.0, 34.0 or 44.0 must be uninstalled first and then reinstalled. On a site where SAML is the only login method, uninstalling the plugin locks every user out, administrators included, so confirm you have a working local Joomla Super User account and a current backup before you start. If the plugin was customised for you, save its configuration and tell miniOrange before replacing it. NOTE ON THE CVE RECORD: as at 26 August 2026 the published CVE record still gives its affected range as 1.0.0 to 11.0.1, which describes the free edition only, and it has not been re-scoped to cover the paid editions. This rule set deliberately goes beyond the range stated in the CVE, on the strength of the vendor written statement of the paid fix versions. If you cannot update immediately, disable or remove the extension rather than leaving an anonymous administrator login available.
Affected versions: ≥ 40.0 and < 44.2
Full advisory: our disclosure post
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
Rules current as of 14 September 2026.