Drupal Security Team Publishes 20 Contributed-Project Advisories, 11 for SAML SSO
Site administrators have 20 new contributed-project security advisories to assess after the Drupal Security Team published its 9 September 2026 disclosure batch. The team rated nine Critical and 11 Moderately Critical. Eleven notices affect SAML SSO - Service Provider, and all 11 are addressed in version 3.2.0.
The practical response differs across the ten affected projects. Most advisories can be addressed with version updates, but Ultimate Table Field also requires a new permission assignment and Patreon has no corrective release. The batch is also concentrated, with 11 notices tied to a single authentication integration.
SAML SSO - Service Provider accounts for SA-CONTRIB-2026-141 through SA-CONTRIB-2026-151. Four Critical advisories cover improper access control, improper certificate validation, an open redirect, and weak cryptographic practices. Seven Moderately Critical advisories cover an authentication bypass, two cross-site scripting issues, embedded credentials, information disclosure, insufficient replay protection, and server-side request forgery. All versions below 3.2.0 are affected, and the advisories direct users to upgrade to 3.2.0.
Drupal.org's release history shows that 3.2.0 is the project's third security release of 2026. An advisory published on 25 February 2026 identified a Critical reflected cross-site scripting vulnerability affecting versions below 3.1.3, which was fixed in version 3.1.3. A second advisory published on 1 April 2026 disclosed a Critical authentication bypass affecting versions below 3.1.4, which was fixed in version 3.1.4. Those were separate disclosures from the 11 advisories addressed by version 3.2.0.
Two other projects received Critical SQL injection advisories. amazee.ai Private AI Provider, SA-CONTRIB-2026-134, is affected below version 1.3.7 and from 1.4.0 through 1.4.2 when a reachable Search API AI Search index uses the PostgreSQL or pgvector backend and exposes a non-string field as a filter. Fixed releases are 1.3.7 and 1.4.3. CSP log, SA-CONTRIB-2026-136, is affected below 1.0.2, and exploitation requires an account with the Access CSP reports permission. The advisory directs users to upgrade to 1.0.2.
Two further Critical advisories affect functionality reachable without authentication. Taxonomy Term Glossary, SA-CONTRIB-2026-152, can expose unpublished or otherwise restricted taxonomy terms through an anonymous JSON endpoint and should be updated to 4.6.0. Ultimate Table Field, SA-CONTRIB-2026-153, exposes its cell-editor route to anonymous users and allows uploads with PDF, DOC, and DOCX file extensions on affected versions.
Ultimate Table Field requires more than a package update. Sites on the 1.x branch should upgrade to version 1.1.1, while sites on the 2.x branch should upgrade to 2.0.1. Releases on the 1.0.x branch are unsupported. After updating, administrators must grant the new Use the Ultimate Table Field cell editor permission to every role that edits content containing an Ultimate Table field. Editors without the permission can no longer open the cell-editor dialog.
Patreon, SA-CONTRIB-2026-139, has no corrective release. The Drupal Security Team marked the project unsupported because a known security issue remains unfixed by the maintainer. Sites using the project are advised to uninstall it rather than wait for an update.
The remaining four Moderately Critical advisories have corrective releases. Central Authentication System (CAS) Server, SA-CONTRIB-2026-135, fixes an open redirect in versions 2.0.4 and 2.1.3. Feed Block, SA-CONTRIB-2026-137, addresses stored cross-site scripting in versions 2.0.2 and 3.0.2. Key auth, SA-CONTRIB-2026-138, fixes cached authentication-key disclosure in version 2.2.4. SafeDelete, SA-CONTRIB-2026-140, addresses stored cross-site scripting in version 1.0.88.
Each of the 9 September advisories lists exploit availability as theoretical. Drupal assigns its Critical and Moderately Critical labels through a 25-point security-risk system based on the NIST Common Misuse Scoring System rather than the Common Vulnerability Scoring System. The calculation considers access complexity, authentication requirements, confidentiality impact, integrity impact, exploit availability, and target distribution.
Drupal's advisory archive records 15 contributed-project advisories dated 26 August 2026, followed by 16 on 2 September and 20 on 9 September. That produces 51 advisories across the three consecutive Wednesday disclosure dates. The figure does not represent 51 separate projects because the latest batch alone contains 11 notices for SAML SSO - Service Provider.
References
-
miniorange_saml 3.2.0 (9 September 2026)
-
CSP log - Critical - SQL Injection - SA-CONTRIB-2026-136 (9 September 2026)
-
Taxonomy Term Glossary - Critical - Access bypass - SA-CONTRIB-2026-152 (9 September 2026)
-
Ultimate Table Field - Critical - Access bypass - SA-CONTRIB-2026-153 (9 September 2026)
-
Patreon - Critical - Unsupported - SA-CONTRIB-2026-139 (9 September 2026)
-
Key auth - Moderately critical - Access bypass - SA-CONTRIB-2026-138 (9 September 2026)
