Drupal Security Team Publishes 20 Contributed-Project Advisories, 11 for SAML SSO
Site administrators have 20 new contributed-project security advisories to assess after the Drupal Security Team published its 9 September 2026 disclosure batch. Nine are rated Critical and 11 Moderately Critical. Eleven notices affect SAML SSO - Service Provider, and users of affected versions are directed to upgrade to version 3.2.0.
The practical response differs across the ten affected projects. Most advisories have corrective releases, but Ultimate Table Field also requires administrators to assign a new permission after updating, while Patreon has no corrective release and should be uninstalled. The batch is heavily concentrated in SAML SSO - Service Provider, which accounts for SA-CONTRIB-2026-141 through SA-CONTRIB-2026-151.
Four Critical SAML SSO advisories cover improper access control, improper certificate validation, an open redirect, and weak cryptographic practices. Seven Moderately Critical advisories cover authentication bypass, two cross-site scripting issues, embedded credentials, information disclosure, insufficient replay protection, and server-side request forgery. All affected versions are below 3.2.0, and each of the 11 advisories directs users to upgrade to that release.
Two other Critical advisories concern SQL injection. amazee.ai Private AI Provider, SA-CONTRIB-2026-134, has fixes in versions 1.3.7 and 1.4.3, depending on the branch in use. CSP log, SA-CONTRIB-2026-136, should be updated to 1.0.2; exploitation requires an account with the Access CSP reports permission.
Two further Critical advisories affect functionality reachable without authentication. Taxonomy Term Glossary, SA-CONTRIB-2026-152, can expose unpublished or otherwise restricted taxonomy terms through an anonymous JSON endpoint and should be updated to 4.6.0. Ultimate Table Field, SA-CONTRIB-2026-153, insufficiently protects its cell-editor route, allowing anonymous users to open the dialog and upload files with PDF, DOC, or DOCX extensions on affected versions.
Ultimate Table Field requires an additional configuration change after the package update. Sites on the 1.x branch should upgrade to 1.1.1, while sites on 2.x should upgrade to 2.0.1; releases on the 1.0.x branch are unsupported. Administrators must then grant the new Use the Ultimate Table Field cell editor permission to roles that edit content containing an Ultimate Table field.
Patreon, SA-CONTRIB-2026-139, has no corrective release. The Drupal Security Team marked the project unsupported because a known security issue remains unfixed and directs sites using it to uninstall the module. The remaining Moderately Critical advisories have corrective releases: Central Authentication System (CAS) Server in 2.0.4 and 2.1.3, Feed Block in 2.0.2 and 3.0.2, Key auth in 2.2.4, and SafeDelete in 1.0.88.
Drupal's advisory archive records 15 contributed-project advisories dated 26 August 2026, followed by 16 on 2 September and 20 on 9 September. That amounts to 51 advisories across three consecutive Wednesday disclosure dates, but not 51 separate affected projects; the 9 September batch alone contains 11 notices for SAML SSO - Service Provider. Administrators should follow the remediation instructions in each advisory for the contributed projects installed on their sites.
References
-
miniorange_saml 3.2.0 (9 September 2026)
-
CSP log - Critical - SQL Injection - SA-CONTRIB-2026-136 (9 September 2026)
-
Taxonomy Term Glossary - Critical - Access bypass - SA-CONTRIB-2026-152 (9 September 2026)
-
Ultimate Table Field - Critical - Access bypass - SA-CONTRIB-2026-153 (9 September 2026)
-
Patreon - Critical - Unsupported - SA-CONTRIB-2026-139 (9 September 2026)
-
Key auth - Moderately critical - Access bypass - SA-CONTRIB-2026-138 (9 September 2026)
