—
DRUPAL-CONTRIB-2026-007
Details
This module enables you to turn a Drupal install into the Central Authentication System (CAS). It makes your database the primary location for other systems to use for authentication in a SSO environment.
The module doesn't sufficiently sanitize user-supplied field values configured to be included as attributes in a CAS server response.
This vulnerability is mitigated by the fact that an attacker must be authenticated, have the ability to enter XML into a user entity field, and that field be configured as a CAS Attribute source leading to an XML Element Injection vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/cas_server
Introduced in:
0Fixed in: 2.0.3Upgrade drupal/cas_server to 2.0.3 or newer (ecosystem packagist:https://packages.drupal.org/8).