Signal

Critical authentication bypass vulnerability found in Drupal SAML SSO module

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-04-01 19:43 UTCUpdated 2026-04-02 02:00 UTC
rss
cvesecurity_advisoryvulnerabilitypatchauthentication_bypass
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
Drupal security advisory (AV26-308)
Canadian Centre for Cyber Security - Alerts · News · cyber.gc.ca · 2026-04-01 19:43 UTC
limited source diversity in top sources
Overview

On April 1, 2026, Drupal released a security advisory addressing a critical authentication bypass vulnerability (CVE-2026-5343) in the SAML SSO - Service Provider module affecting versions prior to 3.1.4. The flaw allows unauthorized access due to insufficient access controls, with a CVSSv3.1 score of 9.8.

Entities
Drupal
Score total
1
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • The advisory and patch were released on April 1, 2026, making immediate action necessary.
  • Drupal sites using the SAML SSO module prior to version 3.1.4 remain vulnerable until updated.
  • Early awareness helps administrators mitigate risks before active exploitation occurs.
Why it matters
  • The vulnerability allows attackers to bypass authentication, risking unauthorized access to Drupal sites.
  • High CVSS score (9.8) indicates critical impact on confidentiality, integrity, and availability.
  • Prompt patching is essential to protect affected systems from potential exploitation.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • Drupal SAML SSO - Service Provider module has a critical authentication bypass vulnerability in versions prior to 3.1.4
How sources frame it
  • Canadian Centre For Cyber Security: neutral
  • Drupal Security Advisories: neutral
All evidence
All evidence
Drupal SAML SSO - Service Provider - Critical - Authentication bypass - SA-CONTRIB-2026-031
NCSC-FI - Vulnerabilities · drupal.org · 2026-04-02 02:00 UTC
Drupal security advisory (AV26-308)
Canadian Centre for Cyber Security - Alerts · cyber.gc.ca · 2026-04-01 19:43 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • NCSC-FI - Vulnerabilities (1)
  • Canadian Centre for Cyber Security - Alerts (1)
Top origin domains (this list)
  • drupal.org (1)
  • cyber.gc.ca (1)