PT-2026-84983 · Mendix · Mendix Saml

CVE-2026-80465

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

8.7

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mendix SAML (Mendix 10 compatible) versions prior to 4.2.3 Mendix SAML (Mendix 11 compatible) versions prior to 4.2.3 Mendix SAML (Mendix 9.24 compatible) versions prior to 3.6.27
Description Certain versions of the Mendix SAML module fail to properly validate the SAML response signature. In specific Single Sign-On (SSO) configurations, this improper verification of cryptographic signatures allows an unauthenticated remote attacker to craft or manipulate a SAML response. If the malicious response is accepted, the attacker can hijack a legitimate authenticated session and gain unauthorized account access, potentially exposing enterprise application data, user privileges, and internal workflows.
Recommendations Update Mendix SAML (Mendix 10 compatible) to version 4.2.3 or later. Update Mendix SAML (Mendix 11 compatible) to version 4.2.3 or later. Update Mendix SAML (Mendix 9.24 compatible) to version 3.6.27 or later.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80465

Affected Products

Mendix Saml