Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index

miniOrange OAuth Client security vulnerabilities

mySites.guru tracks 4 vulnerabilities in com_miniorange_oauth. Every connected Joomla site is checked against them on each audit, and flagged if it runs an affected version.

What we check for

CriticalCVE-2026-779952026-08-24

miniOrange OAuth Client (com_miniorange_oauth) 1.0.0 to 3.1.9 - Unauthenticated Account Takeover (CVSS 10.0)

miniOrange OAuth Client versions 1.0.0 to 3.1.9 are affected by an unauthenticated account takeover, CVE-2026-77995, scored CVSS 4.0 10.0 (critical). Manipulation of a cookie value allows an attacker with no login to authenticate as an arbitrary account, Super Users included. Update the miniOrange OAuth Client to 3.2.0 or later. IMPORTANT edition caveat: miniOrange ships several separately numbered OIDC editions under this same com_miniorange_oauth element, including Login with Azure AD, Login with Keycloak OAuth Single Sign-On and Single Sign-On for Educational Institutes. miniOrange confirmed in writing on 26 August 2026 that those three are fixed in 1.2.2, not 3.2.0, and that all of the fixed versions they gave apply to the free editions only. Check the display name of the installed extension before acting on a version number, and if the site reports a two-segment version such as 32.0.1 or 34.0.0 it is a paid edition. miniOrange stated in writing on 4 September 2026 that CVE-2026-77995 was associated only with the free OAuth Client and that their investigation found the flaw in no version of the paid OAuth editions, which is why no paid security build was ever released. This rule's ceiling of 3.1.9 therefore excludes every paid build on purpose, and no paid install has ever been flagged by it. Note that this rests on the vendor's assessment: the CVE record still names a single product with no edition qualifier, and the same vendor scoped the SAML record to the free line before it had to be widened to name all four paid editions.

Affected versions: ≥ 1.0.0 and ≤ 3.1.9

Full advisory: our disclosure post

HighCVE-2026-780742026-08-31

miniOrange OAuth Client (com_miniorange_oauth) free edition 1.0.0 to 3.2.0 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)

CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "miniOrange Oauth Client (free)", at the CVE's stated affected range 1.0.0-3.2.0. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update the miniOrange OAuth Client to 3.2.1 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 3.2.1 with that release date. Note that 3.2.1 supersedes the 3.2.0 that fixed the separate CVE-2026-77995 account takeover, so a site sitting on 3.2.0 is patched for that flaw but still exposed to this one. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.

Affected versions: ≥ 1.0.0 and ≤ 3.2.0

Full advisory: www.cve.org

HighCVE-2026-780742026-08-31

miniOrange Login with Azure AD / OAuth OIDC SSO (com_miniorange_oauth) free edition 1.0.0 to 1.2.2 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)

CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "OAuth Single Sign-On - OIDC SSO | Login with Azure AD (free)", at the CVE's stated affected range 1.0.0-1.2.2. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update OAuth Single Sign-On - OIDC SSO / Login with Azure AD to 1.2.3 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 1.2.3 with that release date. This product ships under the same com_miniorange_oauth element as the OAuth Client but on its own 1.x numbering, so it is matched on the display name rather than the element alone. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.

Affected versions: ≥ 1.0.0 and ≤ 1.2.2

Full advisory: www.cve.org

HighCVE-2026-780742026-08-31

miniOrange OAuth Server (com_miniorange_oauth) free edition 1.0.0 to 5.1.5 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)

CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "OAuth Server for Joomla (free)", at the CVE's stated affected range 1.0.0-5.1.5. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange OAuth Server to 5.1.6 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 5.1.6 with that release date. This product ships under the same com_miniorange_oauth element as the OAuth Client, so it is matched on the display name rather than the element alone. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.

Affected versions: ≥ 1.0.0 and ≤ 5.1.5

Full advisory: www.cve.org

Running miniOrange OAuth Client on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

CVE identifiers: CVE-2026-77995, CVE-2026-78074. Rules current as of 13 September 2026.