miniOrange SAML SSO (com_miniorange_saml) - Unauthenticated Authentication Bypass (CVSS 10.0)
miniOrange SAML SSO for Joomla is affected by an unauthenticated authentication bypass, CVE-2026-77998, scored CVSS 4.0 10.0 (critical). UtilitiesSAML::validateSignature() performs a loose boolean check on the tri-state integer returned by PHP openssl_verify(), so the error return value of -1 is treated as truthy and therefore as a successful signature verification. An unauthenticated attacker can submit a crafted SAMLResponse holding an attacker-controlled NameID together with a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely and logging in as any existing user, administrators included. FIXED VERSIONS: miniOrange ships this extension as several separately numbered editions, and the leading digit identifies the EDITION rather than the age, so a higher version number is not necessarily newer. Free edition is fixed in 11.0.2 (and 6.4 for the ADFS and Google Apps editions). The paid SAML SP editions were announced to miniOrange customers on 26 August 2026 and confirmed publicly the same day by David Jardin of the Joomla Security Strike Team: Basic is affected up to 13.1 and fixed in 13.2; Standard is affected up to 24.1 and fixed in 24.2; Premium is affected up to 34.1 and fixed in 34.2; Enterprise is affected up to 44.1 and fixed in 44.2. UPDATE PATH WARNING: miniOrange state that 13.0, 13.1, 24.0, 24.1, 34.0, 34.1, 44.0 and 44.1 can install the fixed release directly over the top, but anything below 13.0, 24.0, 34.0 or 44.0 must be uninstalled first and then reinstalled. On a site where SAML is the only login method, uninstalling the plugin locks every user out, administrators included, so confirm you have a working local Joomla Super User account and a current backup before you start. If the plugin was customised for you, save its configuration and tell miniOrange before replacing it. NOTE ON THE CVE RECORD: as at 26 August 2026 the published CVE record still gives its affected range as 1.0.0 to 11.0.1, which describes the free edition only, and it has not been re-scoped to cover the paid editions. This rule set deliberately goes beyond the range stated in the CVE, on the strength of the vendor written statement of the paid fix versions. If you cannot update immediately, disable or remove the extension rather than leaving an anonymous administrator login available.
Affected versions: ≥ 1.0.0 and < 11.0.2
Full advisory: our disclosure post
miniOrange SAML SSO (com_miniorange_saml) - Unauthenticated Authentication Bypass (CVSS 10.0)
miniOrange SAML SSO for Joomla is affected by an unauthenticated authentication bypass, CVE-2026-77998, scored CVSS 4.0 10.0 (critical). UtilitiesSAML::validateSignature() performs a loose boolean check on the tri-state integer returned by PHP openssl_verify(), so the error return value of -1 is treated as truthy and therefore as a successful signature verification. An unauthenticated attacker can submit a crafted SAMLResponse holding an attacker-controlled NameID together with a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely and logging in as any existing user, administrators included. FIXED VERSIONS: miniOrange ships this extension as several separately numbered editions, and the leading digit identifies the EDITION rather than the age, so a higher version number is not necessarily newer. Free edition is fixed in 11.0.2 (and 6.4 for the ADFS and Google Apps editions). The paid SAML SP editions were announced to miniOrange customers on 26 August 2026 and confirmed publicly the same day by David Jardin of the Joomla Security Strike Team: Basic is affected up to 13.1 and fixed in 13.2; Standard is affected up to 24.1 and fixed in 24.2; Premium is affected up to 34.1 and fixed in 34.2; Enterprise is affected up to 44.1 and fixed in 44.2. UPDATE PATH WARNING: miniOrange state that 13.0, 13.1, 24.0, 24.1, 34.0, 34.1, 44.0 and 44.1 can install the fixed release directly over the top, but anything below 13.0, 24.0, 34.0 or 44.0 must be uninstalled first and then reinstalled. On a site where SAML is the only login method, uninstalling the plugin locks every user out, administrators included, so confirm you have a working local Joomla Super User account and a current backup before you start. If the plugin was customised for you, save its configuration and tell miniOrange before replacing it. NOTE ON THE CVE RECORD: as at 26 August 2026 the published CVE record still gives its affected range as 1.0.0 to 11.0.1, which describes the free edition only, and it has not been re-scoped to cover the paid editions. This rule set deliberately goes beyond the range stated in the CVE, on the strength of the vendor written statement of the paid fix versions. If you cannot update immediately, disable or remove the extension rather than leaving an anonymous administrator login available.
Affected versions: ≥ 11.0.3 and < 13.2
Full advisory: our disclosure post
miniOrange SAML SSO (com_miniorange_saml) - Unauthenticated Authentication Bypass (CVSS 10.0)
miniOrange SAML SSO for Joomla is affected by an unauthenticated authentication bypass, CVE-2026-77998, scored CVSS 4.0 10.0 (critical). UtilitiesSAML::validateSignature() performs a loose boolean check on the tri-state integer returned by PHP openssl_verify(), so the error return value of -1 is treated as truthy and therefore as a successful signature verification. An unauthenticated attacker can submit a crafted SAMLResponse holding an attacker-controlled NameID together with a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely and logging in as any existing user, administrators included. FIXED VERSIONS: miniOrange ships this extension as several separately numbered editions, and the leading digit identifies the EDITION rather than the age, so a higher version number is not necessarily newer. Free edition is fixed in 11.0.2 (and 6.4 for the ADFS and Google Apps editions). The paid SAML SP editions were announced to miniOrange customers on 26 August 2026 and confirmed publicly the same day by David Jardin of the Joomla Security Strike Team: Basic is affected up to 13.1 and fixed in 13.2; Standard is affected up to 24.1 and fixed in 24.2; Premium is affected up to 34.1 and fixed in 34.2; Enterprise is affected up to 44.1 and fixed in 44.2. UPDATE PATH WARNING: miniOrange state that 13.0, 13.1, 24.0, 24.1, 34.0, 34.1, 44.0 and 44.1 can install the fixed release directly over the top, but anything below 13.0, 24.0, 34.0 or 44.0 must be uninstalled first and then reinstalled. On a site where SAML is the only login method, uninstalling the plugin locks every user out, administrators included, so confirm you have a working local Joomla Super User account and a current backup before you start. If the plugin was customised for you, save its configuration and tell miniOrange before replacing it. NOTE ON THE CVE RECORD: as at 26 August 2026 the published CVE record still gives its affected range as 1.0.0 to 11.0.1, which describes the free edition only, and it has not been re-scoped to cover the paid editions. This rule set deliberately goes beyond the range stated in the CVE, on the strength of the vendor written statement of the paid fix versions. If you cannot update immediately, disable or remove the extension rather than leaving an anonymous administrator login available.
Affected versions: ≥ 20.0 and < 24.2
Full advisory: our disclosure post
miniOrange SAML SSO (com_miniorange_saml) - Unauthenticated Authentication Bypass (CVSS 10.0)
miniOrange SAML SSO for Joomla is affected by an unauthenticated authentication bypass, CVE-2026-77998, scored CVSS 4.0 10.0 (critical). UtilitiesSAML::validateSignature() performs a loose boolean check on the tri-state integer returned by PHP openssl_verify(), so the error return value of -1 is treated as truthy and therefore as a successful signature verification. An unauthenticated attacker can submit a crafted SAMLResponse holding an attacker-controlled NameID together with a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely and logging in as any existing user, administrators included. FIXED VERSIONS: miniOrange ships this extension as several separately numbered editions, and the leading digit identifies the EDITION rather than the age, so a higher version number is not necessarily newer. Free edition is fixed in 11.0.2 (and 6.4 for the ADFS and Google Apps editions). The paid SAML SP editions were announced to miniOrange customers on 26 August 2026 and confirmed publicly the same day by David Jardin of the Joomla Security Strike Team: Basic is affected up to 13.1 and fixed in 13.2; Standard is affected up to 24.1 and fixed in 24.2; Premium is affected up to 34.1 and fixed in 34.2; Enterprise is affected up to 44.1 and fixed in 44.2. UPDATE PATH WARNING: miniOrange state that 13.0, 13.1, 24.0, 24.1, 34.0, 34.1, 44.0 and 44.1 can install the fixed release directly over the top, but anything below 13.0, 24.0, 34.0 or 44.0 must be uninstalled first and then reinstalled. On a site where SAML is the only login method, uninstalling the plugin locks every user out, administrators included, so confirm you have a working local Joomla Super User account and a current backup before you start. If the plugin was customised for you, save its configuration and tell miniOrange before replacing it. NOTE ON THE CVE RECORD: as at 26 August 2026 the published CVE record still gives its affected range as 1.0.0 to 11.0.1, which describes the free edition only, and it has not been re-scoped to cover the paid editions. This rule set deliberately goes beyond the range stated in the CVE, on the strength of the vendor written statement of the paid fix versions. If you cannot update immediately, disable or remove the extension rather than leaving an anonymous administrator login available.
Affected versions: ≥ 30.0 and < 34.2
Full advisory: our disclosure post
miniOrange SAML SSO (com_miniorange_saml) - Unauthenticated Authentication Bypass (CVSS 10.0)
miniOrange SAML SSO for Joomla is affected by an unauthenticated authentication bypass, CVE-2026-77998, scored CVSS 4.0 10.0 (critical). UtilitiesSAML::validateSignature() performs a loose boolean check on the tri-state integer returned by PHP openssl_verify(), so the error return value of -1 is treated as truthy and therefore as a successful signature verification. An unauthenticated attacker can submit a crafted SAMLResponse holding an attacker-controlled NameID together with a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely and logging in as any existing user, administrators included. FIXED VERSIONS: miniOrange ships this extension as several separately numbered editions, and the leading digit identifies the EDITION rather than the age, so a higher version number is not necessarily newer. Free edition is fixed in 11.0.2 (and 6.4 for the ADFS and Google Apps editions). The paid SAML SP editions were announced to miniOrange customers on 26 August 2026 and confirmed publicly the same day by David Jardin of the Joomla Security Strike Team: Basic is affected up to 13.1 and fixed in 13.2; Standard is affected up to 24.1 and fixed in 24.2; Premium is affected up to 34.1 and fixed in 34.2; Enterprise is affected up to 44.1 and fixed in 44.2. UPDATE PATH WARNING: miniOrange state that 13.0, 13.1, 24.0, 24.1, 34.0, 34.1, 44.0 and 44.1 can install the fixed release directly over the top, but anything below 13.0, 24.0, 34.0 or 44.0 must be uninstalled first and then reinstalled. On a site where SAML is the only login method, uninstalling the plugin locks every user out, administrators included, so confirm you have a working local Joomla Super User account and a current backup before you start. If the plugin was customised for you, save its configuration and tell miniOrange before replacing it. NOTE ON THE CVE RECORD: as at 26 August 2026 the published CVE record still gives its affected range as 1.0.0 to 11.0.1, which describes the free edition only, and it has not been re-scoped to cover the paid editions. This rule set deliberately goes beyond the range stated in the CVE, on the strength of the vendor written statement of the paid fix versions. If you cannot update immediately, disable or remove the extension rather than leaving an anonymous administrator login available.
Affected versions: ≥ 40.0 and < 44.2
Full advisory: our disclosure post
miniOrange SAML SSO (com_miniorange_saml) free edition 1.0.0 to 11.0.2 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)
CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "SAML SSO for Joomla (free)", at the CVE's stated affected range 1.0.0-11.0.2. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange SAML SSO for Joomla to 11.0.3 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 11.0.3 with that release date. Connected sites have already been observed reporting 11.0.3. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.
Affected versions: ≥ 1.0.0 and ≤ 11.0.2
Full advisory: www.cve.org