IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Siemens Mendix SAML

HIGH
CVSS 8.7
Date 2026-09-15T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-80465 8.7 high
CVE-2026-80465. Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations.

// Remediations (6)

Patch: Update to V4.2.3 or later version
Update to V4.2.3 or later version
Patch: Update to V3.6.27 or later version
Update to V3.6.27 or later version
Patch: Update to V4.2.3 or later version
Update to V4.2.3 or later version
Patch: Update to V4.2.3 or later version
Update to V4.2.3 or later version
Patch: Update to V4.2.3 or later version
Update to V4.2.3 or later version
Patch: Update to V3.6.27 or later version
Update to V3.6.27 or later version

// References