Affected versions: ≥ 1.0.0 and < 11.0.2
Full advisory: our disclosure post
miniOrange SAML SSO for Joomla is affected by an unauthenticated authentication bypass, CVE-2026-77998, scored CVSS 4.0 10.0 (critical). UtilitiesSAML::validateSignature() performs a loose boolean check on the tri-state integer returned by PHP openssl_verify(), so the error return value of -1 is treated as truthy and therefore as a successful signature verification. An unauthenticated attacker can submit a crafted SAMLResponse holding an attacker-controlled NameID together with a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely and logging in as any existing user, administrators included. FIXED VERSIONS: miniOrange ships this extension as several separately numbered editions, and the leading digit identifies the EDITION rather than the age, so a higher version number is not necessarily newer. Free edition is fixed in 11.0.2 (and 6.4 for the ADFS and Google Apps editions). The paid SAML SP editions were announced to miniOrange customers on 26 August 2026 and confirmed publicly the same day by David Jardin of the Joomla Security Strike Team: Basic is affected up to 13.1 and fixed in 13.2; Standard is affected up to 24.1 and fixed in 24.2; Premium is affected up to 34.1 and fixed in 34.2; Enterprise is affected up to 44.1 and fixed in 44.2. UPDATE PATH WARNING: miniOrange state that 13.0, 13.1, 24.0, 24.1, 34.0, 34.1, 44.0 and 44.1 can install the fixed release directly over the top, but anything below 13.0, 24.0, 34.0 or 44.0 must be uninstalled first and then reinstalled. On a site where SAML is the only login method, uninstalling the plugin locks every user out, administrators included, so confirm you have a working local Joomla Super User account and a current backup before you start. If the plugin was customised for you, save its configuration and tell miniOrange before replacing it. NOTE ON THE CVE RECORD: as at 26 August 2026 the published CVE record still gives its affected range as 1.0.0 to 11.0.1, which describes the free edition only, and it has not been re-scoped to cover the paid editions. This rule set deliberately goes beyond the range stated in the CVE, on the strength of the vendor written statement of the paid fix versions. If you cannot update immediately, disable or remove the extension rather than leaving an anonymous administrator login available.
CVE-2026-77998 is checked by 5 rules. Find the extension and release line your site runs:
| Extension | Affected versions | Fixed in | What to do |
|---|---|---|---|
| miniOrange SAML SSO | from 1.0.0 up to but not including 11.0.2 | 11.0.2 | Update miniOrange SAML SSO to 11.0.2 for this flaw, or to 44.2 or later, which no rule we check matches. |
| miniOrange SAML SSO | from 11.0.3 up to but not including 13.2 | 13.2 | Update miniOrange SAML SSO to 13.2 or later. |
| miniOrange SAML SSO | from 20.0 up to but not including 24.2 | 24.2 | Update miniOrange SAML SSO to 24.2 or later. |
| miniOrange SAML SSO | from 30.0 up to but not including 34.2 | 34.2 | Update miniOrange SAML SSO to 34.2 or later. |
| miniOrange SAML SSO | from 40.0 up to but not including 44.2 | 44.2 | Update miniOrange SAML SSO to 44.2 or later. |
The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.
10.0 Critical
CVSS 4.0, scored by Joomla CNACVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HAffected versions: ≥ 1.0.0 and < 11.0.2
Full advisory: our disclosure post
miniOrange SAML SSO - miniOrange SAML SSO (com_miniorange_saml) - Unauthenticated Authentication Bypass (CVSS 10.0)
miniOrange SAML SSO for Joomla is affected by an unauthenticated authentication bypass, CVE-2026-77998, scored CVSS 4.0 10.0 (critical). UtilitiesSAML::validateSignature() performs a loose boolean check on the tri-state integer returned by PHP openssl_verify(), so the error return value of -1 is treated as truthy and therefore as a successful signature verification. An unauthenticated attacker can submit a crafted SAMLResponse holding an attacker-controlled NameID together with a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely and logging in as any existing user, administrators included. FIXED VERSIONS: miniOrange ships this extension as several separately numbered editions, and the leading digit identifies the EDITION rather than the age, so a higher version number is not necessarily newer. Free edition is fixed in 11.0.2 (and 6.4 for the ADFS and Google Apps editions). The paid SAML SP editions were announced to miniOrange customers on 26 August 2026 and confirmed publicly the same day by David Jardin of the Joomla Security Strike Team: Basic is affected up to 13.1 and fixed in 13.2; Standard is affected up to 24.1 and fixed in 24.2; Premium is affected up to 34.1 and fixed in 34.2; Enterprise is affected up to 44.1 and fixed in 44.2. UPDATE PATH WARNING: miniOrange state that 13.0, 13.1, 24.0, 24.1, 34.0, 34.1, 44.0 and 44.1 can install the fixed release directly over the top, but anything below 13.0, 24.0, 34.0 or 44.0 must be uninstalled first and then reinstalled. On a site where SAML is the only login method, uninstalling the plugin locks every user out, administrators included, so confirm you have a working local Joomla Super User account and a current backup before you start. If the plugin was customised for you, save its configuration and tell miniOrange before replacing it. NOTE ON THE CVE RECORD: as at 26 August 2026 the published CVE record still gives its affected range as 1.0.0 to 11.0.1, which describes the free edition only, and it has not been re-scoped to cover the paid editions. This rule set deliberately goes beyond the range stated in the CVE, on the strength of the vendor written statement of the paid fix versions. If you cannot update immediately, disable or remove the extension rather than leaving an anonymous administrator login available.
Affected versions: ≥ 11.0.3 and < 13.2
Full advisory: our disclosure post
miniOrange SAML SSO - miniOrange SAML SSO (com_miniorange_saml) - Unauthenticated Authentication Bypass (CVSS 10.0)
miniOrange SAML SSO for Joomla is affected by an unauthenticated authentication bypass, CVE-2026-77998, scored CVSS 4.0 10.0 (critical). UtilitiesSAML::validateSignature() performs a loose boolean check on the tri-state integer returned by PHP openssl_verify(), so the error return value of -1 is treated as truthy and therefore as a successful signature verification. An unauthenticated attacker can submit a crafted SAMLResponse holding an attacker-controlled NameID together with a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely and logging in as any existing user, administrators included. FIXED VERSIONS: miniOrange ships this extension as several separately numbered editions, and the leading digit identifies the EDITION rather than the age, so a higher version number is not necessarily newer. Free edition is fixed in 11.0.2 (and 6.4 for the ADFS and Google Apps editions). The paid SAML SP editions were announced to miniOrange customers on 26 August 2026 and confirmed publicly the same day by David Jardin of the Joomla Security Strike Team: Basic is affected up to 13.1 and fixed in 13.2; Standard is affected up to 24.1 and fixed in 24.2; Premium is affected up to 34.1 and fixed in 34.2; Enterprise is affected up to 44.1 and fixed in 44.2. UPDATE PATH WARNING: miniOrange state that 13.0, 13.1, 24.0, 24.1, 34.0, 34.1, 44.0 and 44.1 can install the fixed release directly over the top, but anything below 13.0, 24.0, 34.0 or 44.0 must be uninstalled first and then reinstalled. On a site where SAML is the only login method, uninstalling the plugin locks every user out, administrators included, so confirm you have a working local Joomla Super User account and a current backup before you start. If the plugin was customised for you, save its configuration and tell miniOrange before replacing it. NOTE ON THE CVE RECORD: as at 26 August 2026 the published CVE record still gives its affected range as 1.0.0 to 11.0.1, which describes the free edition only, and it has not been re-scoped to cover the paid editions. This rule set deliberately goes beyond the range stated in the CVE, on the strength of the vendor written statement of the paid fix versions. If you cannot update immediately, disable or remove the extension rather than leaving an anonymous administrator login available.
Affected versions: ≥ 20.0 and < 24.2
Full advisory: our disclosure post
miniOrange SAML SSO - miniOrange SAML SSO (com_miniorange_saml) - Unauthenticated Authentication Bypass (CVSS 10.0)
miniOrange SAML SSO for Joomla is affected by an unauthenticated authentication bypass, CVE-2026-77998, scored CVSS 4.0 10.0 (critical). UtilitiesSAML::validateSignature() performs a loose boolean check on the tri-state integer returned by PHP openssl_verify(), so the error return value of -1 is treated as truthy and therefore as a successful signature verification. An unauthenticated attacker can submit a crafted SAMLResponse holding an attacker-controlled NameID together with a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely and logging in as any existing user, administrators included. FIXED VERSIONS: miniOrange ships this extension as several separately numbered editions, and the leading digit identifies the EDITION rather than the age, so a higher version number is not necessarily newer. Free edition is fixed in 11.0.2 (and 6.4 for the ADFS and Google Apps editions). The paid SAML SP editions were announced to miniOrange customers on 26 August 2026 and confirmed publicly the same day by David Jardin of the Joomla Security Strike Team: Basic is affected up to 13.1 and fixed in 13.2; Standard is affected up to 24.1 and fixed in 24.2; Premium is affected up to 34.1 and fixed in 34.2; Enterprise is affected up to 44.1 and fixed in 44.2. UPDATE PATH WARNING: miniOrange state that 13.0, 13.1, 24.0, 24.1, 34.0, 34.1, 44.0 and 44.1 can install the fixed release directly over the top, but anything below 13.0, 24.0, 34.0 or 44.0 must be uninstalled first and then reinstalled. On a site where SAML is the only login method, uninstalling the plugin locks every user out, administrators included, so confirm you have a working local Joomla Super User account and a current backup before you start. If the plugin was customised for you, save its configuration and tell miniOrange before replacing it. NOTE ON THE CVE RECORD: as at 26 August 2026 the published CVE record still gives its affected range as 1.0.0 to 11.0.1, which describes the free edition only, and it has not been re-scoped to cover the paid editions. This rule set deliberately goes beyond the range stated in the CVE, on the strength of the vendor written statement of the paid fix versions. If you cannot update immediately, disable or remove the extension rather than leaving an anonymous administrator login available.
Affected versions: ≥ 30.0 and < 34.2
Full advisory: our disclosure post
miniOrange SAML SSO - miniOrange SAML SSO (com_miniorange_saml) - Unauthenticated Authentication Bypass (CVSS 10.0)
miniOrange SAML SSO for Joomla is affected by an unauthenticated authentication bypass, CVE-2026-77998, scored CVSS 4.0 10.0 (critical). UtilitiesSAML::validateSignature() performs a loose boolean check on the tri-state integer returned by PHP openssl_verify(), so the error return value of -1 is treated as truthy and therefore as a successful signature verification. An unauthenticated attacker can submit a crafted SAMLResponse holding an attacker-controlled NameID together with a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely and logging in as any existing user, administrators included. FIXED VERSIONS: miniOrange ships this extension as several separately numbered editions, and the leading digit identifies the EDITION rather than the age, so a higher version number is not necessarily newer. Free edition is fixed in 11.0.2 (and 6.4 for the ADFS and Google Apps editions). The paid SAML SP editions were announced to miniOrange customers on 26 August 2026 and confirmed publicly the same day by David Jardin of the Joomla Security Strike Team: Basic is affected up to 13.1 and fixed in 13.2; Standard is affected up to 24.1 and fixed in 24.2; Premium is affected up to 34.1 and fixed in 34.2; Enterprise is affected up to 44.1 and fixed in 44.2. UPDATE PATH WARNING: miniOrange state that 13.0, 13.1, 24.0, 24.1, 34.0, 34.1, 44.0 and 44.1 can install the fixed release directly over the top, but anything below 13.0, 24.0, 34.0 or 44.0 must be uninstalled first and then reinstalled. On a site where SAML is the only login method, uninstalling the plugin locks every user out, administrators included, so confirm you have a working local Joomla Super User account and a current backup before you start. If the plugin was customised for you, save its configuration and tell miniOrange before replacing it. NOTE ON THE CVE RECORD: as at 26 August 2026 the published CVE record still gives its affected range as 1.0.0 to 11.0.1, which describes the free edition only, and it has not been re-scoped to cover the paid editions. This rule set deliberately goes beyond the range stated in the CVE, on the strength of the vendor written statement of the paid fix versions. If you cannot update immediately, disable or remove the extension rather than leaving an anonymous administrator login available.
Affected versions: ≥ 40.0 and < 44.2
Full advisory: our disclosure post
Updating for CVE-2026-77998 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.
Latest safe version: 44.2
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.
Rules current as of 5 October 2026.