← All CVEs NewScan detects
high

CVE-2026-75807

SAML Single Sign On - SSO Login (miniOrange) authentication bypass - mo_saml_login_validate() trusts an unverified assertion, so any account can be logged into

Severity
high
Affected product
miniorange-saml-20-single-sign-on
Affected versions
miniorange-saml-20-single-sign-on ≤ 5.4.6
Fixed in
miniorange-saml-20-single-sign-on 5.4.7
Added to NewScan
2026-08-30
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints miniorange-saml-20-single-sign-on from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-30 (/daily-cve). Version source: scan_wordpress mines every referenced plugin slug from asset `?ver=` and refines it against /wp-content/plugins/<slug>/readme.txt `Stable tag:` - the same generic per-slug join the other WordPress rows in this pack use, no new code. THE SLUG IS VERIFIED, NOT INFERRED: api.wordpress.org/plugins/info/1.0/miniorange-saml-20-single-sign-on.json answers with 'SAML Single Sign On - SSO Login' at version 5.4.7, which both confirms the directory name the readme join needs AND independently confirms the fix release (the advisory only says 'up to and including 5.4.6'). Version-match only - confirming the bypass in-band means logging into a stranger's site as an arbitrary user.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →