CVE-2026-3217: SAML SSO - Service Provider - Critical - Cross-site scripting - SA-CONTRIB-2026-018
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal SAML SSO - Service Provider allows Cross-Site Scripting (XSS).This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3217?
CVE-2026-3217 is considered a critical vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2026-3217?
To fix CVE-2026-3217, update the Drupal SAML SSO - Service Provider module to version 3.1.4 or later.
What kind of attacks can CVE-2026-3217 facilitate?
CVE-2026-3217 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages.
Which versions of SAML SSO - Service Provider are affected by CVE-2026-3217?
CVE-2026-3217 affects all versions of SAML SSO - Service Provider from 0.0.0 to 3.1.3.
Is user input validation affected by CVE-2026-3217?
Yes, CVE-2026-3217 involves improper neutralization of input during web page generation, which impacts user input validation.