CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-15981: miniOrange SAML Authentication Bypass

August 25, 2026

CVE-2026-15981 is a critical authentication bypass vulnerability in the miniOrange SAML 2.0 Single Sign On plugin. It allows unauthenticated attackers to log in as any WordPress user, including administrators, by submitting a crafted SAMLResponse with a malformed signature. The flaw is due to a loose boolean check on the return value of openssl_verify(). Fixed in version 17.0.6.