Skip to main content
QUIETLYTIC
Vulnerability

SAML Single Sign On – SSO Login Authentication Bypass (CVE-2026-15981)

CVE-2026-15981 is a CVSS 9.8 authentication bypass in the MiniOrange SAML SSO WordPress plugin allowing login as any user, reported exploited by VulnCheck.

CVE-2026-15981
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
SAML Single Sign On – SSO Login, MiniOrange SAML SP Single Sign On (through 5.4.4)

CVE-2026-15981 carries a CVSS 3.1 base score of 9.8 against SAML Single Sign On – SSO Login, a WordPress plugin published by MiniOrange for SAML-based authentication. NVD classifies it as CWE-287 (Improper Authentication) and states the flaw affects all versions up to and including 5.4.4. VulnCheck’s KEV feed reports the CVE as exploited, dated August 21, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-15981 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description identifies a specific type-handling error in the plugin’s mo_saml_validate_signature() function. PHP’s built-in openssl_verify() function returns a tri-state integer: 1 for a valid signature, 0 for an invalid one, and -1 for a processing error distinct from either. NVD states the plugin performs a loose boolean check on that return value rather than an exact comparison — and in PHP, the integer -1 evaluates as truthy in a loose boolean context, so an OpenSSL processing error is treated identically to a successful signature verification.

The practical consequence, per NVD, is that an unauthenticated attacker can submit a SAML response containing an attacker-controlled NameID (the field identifying which user to log in as) paired with a deliberately malformed signature value engineered to trigger an OpenSSL processing error rather than a clean pass/fail result. Because that error return is misread as success, NVD states the plugin proceeds to call WordPress’s own session-creation function for the attacker-specified account — including, potentially, an administrator account.

Evidence and confidence

  • Medium confidence — the CVSS 9.8 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-287 classification, the affected-version ceiling (5.4.4), and the specific type-confusion mechanism all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone.
  • Above-midpoint exploitation probability — FIRST’s EPSS model scores this CVE at 0.00815, a 55.3rd percentile score as of our ingestion.

No field is in conflict between our two sources. Our data carries no fixed-version field beyond NVD’s affected-version ceiling.

Why this matters

This is a textbook example of why SAML and other cryptographic-signature implementations carry outsized risk from small implementation errors: the plugin’s core security guarantee — that only correctly signed assertions are accepted — is entirely undone by a language-level truthiness quirk in how one function’s return value is checked, with no separate logical flaw needed elsewhere. Any site relying on this plugin for SAML SSO should treat every account, not just administrators, as potentially reachable by this bypass, since NVD’s description states the attacker chooses which existing user to log in as via the NameID field.

Because SSO plugins are specifically the layer meant to centralize and strengthen authentication, a flaw here can undermine security assumptions built on top of it — access control decisions elsewhere in a site’s architecture that assume “authenticated via SSO” means “verified” no longer hold once this bypass is in play.

Frequently Asked Questions

What is CVE-2026-15981? A CVSS 9.8 authentication bypass vulnerability (CWE-287) in the MiniOrange SAML Single Sign On – SSO Login WordPress plugin, through version 5.4.4, allowing unauthenticated attackers to log in as any existing user, including administrators.

Is CVE-2026-15981 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 21, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.

How does the bypass actually work? NVD states the plugin’s signature-validation function performs a loose boolean check on PHP’s openssl_verify() return value, which can return -1 on a processing error — a value that evaluates as truthy in PHP, causing a failed verification to be treated as successful.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Our data carries no fixed-version field. NVD states versions through 5.4.4 are affected; confirm directly with MiniOrange’s changelog whether a later release addresses this specific CVE.


Severity, vector, weakness classification, and the full type-confusion mechanism sourced from the National Vulnerability Database record for CVE-2026-15981. Exploitation status and the August 21, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools