Changeflow GovPing Data Privacy & Cybersecurity Drupal SAML SSO Security Bypass Vulnerability A...
Priority review Guidance Added Final

Drupal SAML SSO Security Bypass Vulnerability Advisory

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published April 1st, 2026
Detected April 2nd, 2026
Email

Summary

CERT-Bund issued a security advisory regarding a vulnerability in Drupal SAML SSO module versions prior to 3.1.4. The flaw allows remote attackers to bypass security measures. The vulnerability has a CVSS Base Score of 7.4 (high) and Temporal Score of 6.4 (medium). Organizations using the affected module should apply available mitigations.

What changed

CERT-Bund published advisory WID-SEC-2026-0954 disclosing a security bypass vulnerability in Open Source Drupal SAML SSO versions below 3.1.4. The vulnerability enables remote attackers to circumvent security controls. CVSS Base Score is 7.4 (high severity) with a Temporal Score of 6.4 (medium). The vulnerability affects Drupal installations across Linux, UNIX, Windows, and other operating systems.

Organizations using Drupal SAML SSO module should immediately verify their current version and upgrade to version 3.1.4 or later to remediate the vulnerability. Where immediate patching is not feasible, apply available mitigations referenced in the advisory. System administrators should monitor for unusual authentication patterns as the bypass could enable unauthorized access to systems protected by SAML SSO.

What to do next

  1. Identify all Drupal installations running SAML SSO module
  2. Check module version; upgrade to 3.1.4 or later if below that version
  3. Apply available mitigations if immediate upgrade is not feasible

Source document (simplified)

[WID-SEC-2026-0954] Drupal (SAML SSO): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen CVSS Base Score 7.4 (hoch) CVSS Temporal Score 6.4 (mittel) Remoteangriff ja Datum 01.04.2026 Stand 02.04.2026 Mitigation ja

Betroffene Systeme

Betriebssystem

  • Linux
  • Sonstiges
  • UNIX
  • Windows

Produktbeschreibung

Drupal ist ein freies Content-Management-System, basierend auf der Scriptsprache PHP und einer SQL-Datenbank. Über zahlreiche Extensions kann der Funktionsumfang der Core-Installation individuell erweitert werden.

Produkte

01.04.2026
- Open Source Drupal SAML SSO <3.1.4

Angriff

Angriff

Ein Angreifer kann eine Schwachstelle in Drupal SAML SSO ausnutzen, um Sicherheitsvorkehrungen zu umgehen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
April 1st, 2026
Instrument
Guidance
Legal weight
Non-binding
Stage
Final
Change scope
Minor
Document ID
WID-SEC-2026-0954

Who this affects

Applies to
Technology companies Government agencies
Industry sector
5112 Software & Technology 5182 Data Processing & Hosting
Activity scope
Software Vulnerability Management System patching
Threshold
Open Source Drupal SAML SSO < 3.1.4
Geographic scope
Germany DE

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Data Privacy Software & Technology

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Optional. Personalizes your daily digest.

Free. Unsubscribe anytime.