Impact
An improper verification of the cryptographic signature in the SAML authentication module allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This weakness, identified as CWE‑347, can give attackers full control over the system and compromise confidentiality, integrity, and availability. The vulnerability directly enables privilege escalation when SAML single sign-on is enabled.
Affected Systems
Progress Software Corporation’s MarkLogic Server is affected in versions prior to 11.3.6 and 12.0.3 when SAML single sign‑on is enabled. Deployments using these versions and relying on SAML for user authentication are at risk.
Risk and Exploitability
The CVSS score of 9.1 indicates critical severity, and the lack of an EPSS score means the exploitation probability is unknown, though the vulnerability is serious enough to warrant immediate attention. The attack vector is a remote attacker submitting a forged or unsigned SAML assertion; the description explicitly states that the attacker need not be authenticated. The vulnerability is not listed in the CISA KEV catalog. When SAML is enabled, a crafted assertion can be sent to the callback endpoint to trigger the bypass, so any exposed endpoint that accepts SAML assertions is a potential entry point.
OpenCVE Enrichment