THREAT OPS › Threat News › CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass (PoC)
CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass (PoC)
<p>Posted by Öner Efe Güngör on Aug 06</p>Hello Full Disclosure,<br /> <br /> I'd like to share an independent lab Proof-of-Concept for CVE-2026-15013.<br /> <br /> ### CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated<br /> Authentication Bypass<br /> <br /> SAML Signature Algorithm Confusion vulnerability. An unauthenticated<br /> attacker can forge a valid SAMLResponse by fo
Indicators of compromise
- CVE-2026-15013cve
Original source: https://seclists.org/fulldisclosure/2026/Aug/33