CVE-2026-15013 – miniOrange SA... Note

CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass (PoC)

Posted by Öner Efe Güngör on Aug 06Hello Full Disclosure, I'd like to share an independent lab Proof-of-Concept for CVE-2026-15013. ### CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass SAML Signature Algorithm Confusion vulnerability. An unauthenticated attacker can forge a valid SAMLResponse by forcing HMAC-SHA1 verification against the IdP's public key, allowing full account takeover (including administrators). Root cause:...