Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
identity-authentication-vulnerabilitywidely-deployed-product-advisoryopen-source-dependency-vulnerabilityendpoint-software-vulnerability

Critical Drupal SAML SSO auth bypass and high-severity Samba flaws disclosed

Updated 1d agoFirst seen Apr 1, 20263 sources

Drupal disclosed SA-CONTRIB-2026-031, a critical authentication bypass vulnerability in the SAML SSO - Service Provider module affecting versions prior to 3.1.4. The Canadian Centre for Cyber Security warned that organizations using the product should review Drupal’s guidance and apply the vendor update, as the flaw could allow unauthorized access through affected single sign-on deployments.

Separately, Samba maintainers announced upcoming security releases for versions 4.22, 4.23, and 4.24 to address six vulnerabilities spanning file services, domain members, and Active Directory Domain Controller components. A follow-up correction said a CVSS 10.0 file-services issue affects uncommon configurations rather than some configurations, and clarified that one Active Directory-related flaw impacts domain members rather than AD domain controllers; administrators were urged to deploy the Samba updates promptly after release.

Share:
Critical Drupal SAML SSO auth bypass and high-severity Samba flaws disclosed
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Apr 7, 20263mo ago

Samba postpones April 9 security releases after fix issue found

Douglas Bagnall announced that the Samba security releases planned for April 9, 2026 were postponed after the team discovered a problem in one of the fixes. Samba said a new release date would be announced as soon as possible and advised administrators to remain ready to update promptly once releases are available.

oss-sec: Re: Re: Heads-up: Upcoming Samba security releases (2026-04-09)
Apr 6, 20263mo ago

Samba corrects scope details for two upcoming vulnerabilities

In a follow-up message, Douglas Bagnall corrected earlier descriptions of two Samba issues, clarifying that a CVSS 10.0 file services flaw affects uncommon configurations and that an Active Directory-related issue affects domain members rather than AD domain controllers. Administrators were advised to update soon after the fixes became available.

Samba announces upcoming April 9 security releases

Douglas Bagnall announced that Samba security updates for versions 4.22, 4.23, and 4.24 were scheduled for release on April 9, 2026. The notice said the release would address six vulnerabilities affecting file services, domain members, and AD DC components, with CVSS scores ranging from 6.5 to 10.0.

Apr 1, 20263mo ago

Drupal discloses critical SAML SSO authentication bypass flaw

Drupal published security advisory SA-CONTRIB-2026-031 for a critical authentication bypass vulnerability in the SAML SSO - Service Provider product affecting versions prior to 3.1.4. The Canadian Centre for Cyber Security urged administrators to review Drupal's guidance and apply the necessary updates.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

1 LINKEDOpen in app
Organizations
1 linked
Drupal
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Critical Drupal SAML SSO auth bypass and high-severity Samba flaws disclosed | Mallory