Description
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
Published: 2026-08-05
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper verification of the cryptographic signature in the SAML authentication module allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This weakness, identified as CWE‑347, can give attackers full control over the system and compromise confidentiality, integrity, and availability. The vulnerability directly enables privilege escalation when SAML single sign-on is enabled.

Affected Systems

Progress Software Corporation’s MarkLogic Server is affected in versions prior to 11.3.6 and 12.0.3 when SAML single sign‑on is enabled. Deployments using these versions and relying on SAML for user authentication are at risk.

Risk and Exploitability

The CVSS score of 9.1 indicates critical severity, and the lack of an EPSS score means the exploitation probability is unknown, though the vulnerability is serious enough to warrant immediate attention. The attack vector is a remote attacker submitting a forged or unsigned SAML assertion; the description explicitly states that the attacker need not be authenticated. The vulnerability is not listed in the CISA KEV catalog. When SAML is enabled, a crafted assertion can be sent to the callback endpoint to trigger the bypass, so any exposed endpoint that accepts SAML assertions is a potential entry point.

Generated by OpenCVE AI on August 5, 2026 at 17:43 UTC.

Remediation

Vendor Workaround

If SAML single sign-on is not required, disable it and use local or LDAP authentication until the update can be applied. Restrict the SAML callback endpoint to known identity-provider networks and monitor authentication logs for anomalous SAML logins.


OpenCVE Recommended Actions

  • Update MarkLogic Server to version 11.3.6 or later, or 12.0.3 or later, when the vendor releases the fix.
  • If the SAML single sign‑on feature is not required, disable it and use local or LDAP authentication until the update can be applied.
  • Restrict the SAML callback endpoint to known identity‑provider networks and monitor authentication logs for anomalous SAML logins.

Generated by OpenCVE AI on August 5, 2026 at 17:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
Title SAML authentication bypass in Progress MarkLogic Server
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-08-05T18:42:22.772Z

Reserved: 2026-04-30T19:27:17.815Z

Link: CVE-2026-7557

cve-icon Vulnrichment

Updated: 2026-08-05T18:14:46.701Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T17:45:16Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature