INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Two CVSS 9.8 Auth Bypasses Exploited in miniOrange SAML Plugin

| 2026-08-25 08:34 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The threat landscape is increasingly complex, with attackers exploiting vulnerabilities in various software applications to gain unauthorized access and manipulate sensitive information. MiniOrange SSO endpoints, a critical component of online security systems, have been identified as a target by malicious actors. These entities are actively scanning six IP addresses from Belgium, Nigeria, the U.S., and Germany, indicating a high level of sophistication and intent. The use of defense in depth measures has proven ineffective against these attackers, who have successfully bypassed authentication mechanisms using CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin. This vulnerability allows unauthenticated attackers to forge SAML authentication responses, effectively gaining access to sensitive information. As a result, organizations must prioritize patching and updating vulnerable software applications, including those used by MiniOrange, to mitigate this threat.
Technical Mitigations AI-generated
* Manual patch required: The CVE-2026-61979 and CVE-2026-15981 vulnerabilities require a manual update to the miniOrange SAML WordPress plugin to fix. * Use of HMAC-SHA1 algorithm: The first vulnerability allows an attacker to forge a SAML authentication response by setting the HMAC-SHA1 algorithm to use the identity provider's RSA public key as the HMAC secret. This can be mitigated by using a more secure signature algorithm, such as HMAC-SHA256 or SHA-512. * Incorrect handling of OpenSSL errors: The second vulnerability allows an attacker to send a specially crafted signature that causes an OpenSSL error, making it appear valid. This can be mitigated by properly handling OpenSSL errors and returning the correct result code (1 for valid, 0 for invalid, -1 for error). * Secure authentication practices: To prevent similar attacks in the future, organizations should ensure that their WordPress installations are using secure authentication practices, such as: * Using a more secure signature algorithm * Properly handling OpenSSL errors and returning correct result codes * Implementing rate limiting on login attempts to prevent brute-force attacks
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

162.243.•••.•••
207.211.•••.•••
102.91.•••.•••
64.225.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-61979CVE-2026-61979 CVE-2026-15981CVE-2026-15981
Target & Sectors
EUROPE EUROPE BENELUX BENELUX NORTH_AMERICA NORTH_AMERICA DACH DACH AFRICA AFRICA
Incident Timeline
‎August 16
DigitalOcean blocked an anomalous WordPress administrator session on August 16.
‎Aug 25, 2026
Attackers exploited an unauthenticated privilege escalation vulnerability in WordPress, specifically the `miniOrange SAML` flaw, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a deliberately malformed signature value that triggered an OpenSSL processing error.
organisation CVE-2026-15981
infrastructure 17.0.5
infrastructure 9.8
infrastructure 17.0.6
organisation PHP
organisation -1
organisation CVE-2026
organisation CVE.org
organisation IP
organisation SAMLResponse
organisation NameID
organisation Patchstack
organisation PoC
‎2026/08/25
Attackers exploited two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that made it possible for an attacker to sign in as any WordPress user, including administrators.
organisation CVE-2026
organisation PHP
organisation CVE-2026-61979
organisation CVSS 9.8 Auth Bypasses
organisation -1
organisation IP
organisation Attackers Target miniOrange SAML Flaws
organisation Vulnerability / Web Security
organisation WordPress
organisation The Blue Report 2026
organisation Patchstack
organisation XML
organisation PoC
infrastructure 5.4.5
infrastructure 13.0.4
infrastructure 17.06
infrastructure 20.2.8
infrastructure 26.0.3
infrastructure 32.0.8
infrastructure 35.0.7
organisation Premium/Enterprise/All-Inclusive
organisation 20.2.8 Enterprise/All-Inclusive
infrastructure 16.1.9
organisation HMAC-SHA1
organisation HMAC
organisation RSA
organisation IdP
organisation WordPress.org
organisation IPs
organisation SecurityAffairs
organisation Microsoft Entra ID
organisation OneLogin
infrastructure 10,000 downloads
victims 30,000 customers
Tactical Metrics
Metrics
infrastructure
‎17.0.5
Software Version
Metrics
infrastructure
‎9.8
Software Version
Metrics
infrastructure
‎17.0.6
Software Version
Metrics
infrastructure
‎5.4.5
Software Version
Metrics
infrastructure
‎16.1.9
Software Version
Metrics
infrastructure
‎13.0.4
Software Version
Metrics
infrastructure
‎17.06
Software Version
Metrics
infrastructure
‎20.2.8
Software Version
Metrics
infrastructure
‎26.0.3
Software Version
Metrics
infrastructure
‎32.0.8
Software Version
Metrics
infrastructure
‎35.0.7
Software Version
Metrics
infrastructure
10,000
Downloads
Metrics
victims
30,000
Customers