IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-887643: Account Hijacking Vulnerability in Mendix SAML module

HIGH
CVSS 8.7
Date 2026-09-03T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-80465 8.7 high
CVE-2026-80465. Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations.

// Remediations (3)

Patch: Update to V4.2.3 or later version
Update to V4.2.3 or later version
Patch: Update to V4.2.3 or later version
Update to V4.2.3 or later version
Patch: Update to V3.6.27 or later version
Update to V3.6.27 or later version

// References