Date: 
2026-September-09
Vulnerability: 
Cross-site scripting
Affected versions: 
<3.2.0
CVE IDs: 
CVE-2026-87948
Description: 

This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.

The module does not sufficiently sanitize user-supplied data before displaying it in generated HTML leading to a cross-site scripting vulnerability (XSS).

Solution: 

Install the latest version:

Coordinated By: