Drupal Security Team Publishes 20 Contributed-Project Advisories, 11 for SAML SSO

Security graphic with the headline "One Release Addresses 11 of 20 Security Advisories" and the text "Updates, a Permission Change, and One Module Removal". The design includes connected module and update icons with "SAML SP" and "amazee.ai" logos plus "Follow us on" and "https://www.thedroptimes.com/" with The Drop Times branding.

Site administrators have 20 new contributed-project security advisories to assess after the Drupal Security Team published its 9 September 2026 disclosure batch. Nine are rated Critical and 11 Moderately Critical. Eleven notices affect SAML SSO - Service Provider, and users of affected versions are directed to upgrade to version 3.2.0.

The practical response differs across the ten affected projects. Most advisories have corrective releases, but Ultimate Table Field also requires administrators to assign a new permission after updating, while Patreon has no corrective release and should be uninstalled. The batch is heavily concentrated in SAML SSO - Service Provider, which accounts for SA-CONTRIB-2026-141 through SA-CONTRIB-2026-151.

Four Critical SAML SSO advisories cover improper access control, improper certificate validation, an open redirect, and weak cryptographic practices. Seven Moderately Critical advisories cover authentication bypass, two cross-site scripting issues, embedded credentials, information disclosure, insufficient replay protection, and server-side request forgery. All affected versions are below 3.2.0, and each of the 11 advisories directs users to upgrade to that release.

Two other Critical advisories concern SQL injection. amazee.ai Private AI Provider, SA-CONTRIB-2026-134, has fixes in versions 1.3.7 and 1.4.3, depending on the branch in use. CSP log, SA-CONTRIB-2026-136, should be updated to 1.0.2; exploitation requires an account with the Access CSP reports permission.

Two further Critical advisories affect functionality reachable without authentication. Taxonomy Term Glossary, SA-CONTRIB-2026-152, can expose unpublished or otherwise restricted taxonomy terms through an anonymous JSON endpoint and should be updated to 4.6.0. Ultimate Table Field, SA-CONTRIB-2026-153, insufficiently protects its cell-editor route, allowing anonymous users to open the dialog and upload files with PDF, DOC, or DOCX extensions on affected versions.

Ultimate Table Field requires an additional configuration change after the package update. Sites on the 1.x branch should upgrade to 1.1.1, while sites on 2.x should upgrade to 2.0.1; releases on the 1.0.x branch are unsupported. Administrators must then grant the new Use the Ultimate Table Field cell editor permission to roles that edit content containing an Ultimate Table field.

Patreon, SA-CONTRIB-2026-139, has no corrective release. The Drupal Security Team marked the project unsupported because a known security issue remains unfixed and directs sites using it to uninstall the module. The remaining Moderately Critical advisories have corrective releases: Central Authentication System (CAS) Server in 2.0.4 and 2.1.3, Feed Block in 2.0.2 and 3.0.2, Key auth in 2.2.4, and SafeDelete in 1.0.88.

Drupal's advisory archive records 15 contributed-project advisories dated 26 August 2026, followed by 16 on 2 September and 20 on 9 September. That amounts to 51 advisories across three consecutive Wednesday disclosure dates, but not 51 separate affected projects; the 9 September batch alone contains 11 notices for SAML SSO - Service Provider. Administrators should follow the remediation instructions in each advisory for the contributed projects installed on their sites.

Disclosure: This content is produced with the assistance of AI.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please reach out to us at #thedroptimes channel on Drupal Slack and we will try to address the issue as best we can.

Upcoming Events

Latest Opportunities