PT-2026-84983 · Mendix · Mendix Saml
CVE-2026-80465
·
Published
2026-09-03
·
Updated
2026-09-03
CVSS v3.1
8.7
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Mendix SAML (Mendix 10 compatible) versions prior to 4.2.3
Mendix SAML (Mendix 11 compatible) versions prior to 4.2.3
Mendix SAML (Mendix 9.24 compatible) versions prior to 3.6.27
Description
Certain versions of the Mendix SAML module fail to properly validate the SAML response signature. In specific Single Sign-On (SSO) configurations, this improper verification of cryptographic signatures allows an unauthenticated remote attacker to craft or manipulate a SAML response. If the malicious response is accepted, the attacker can hijack a legitimate authenticated session and gain unauthorized account access, potentially exposing enterprise application data, user privileges, and internal workflows.
Recommendations
Update Mendix SAML (Mendix 10 compatible) to version 4.2.3 or later.
Update Mendix SAML (Mendix 11 compatible) to version 4.2.3 or later.
Update Mendix SAML (Mendix 9.24 compatible) to version 3.6.27 or later.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mendix Saml