Description
A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations.
Published: 2026-09-03
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Account Hijacking (Unauthenticated Session Takeover)
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in Mendix SAML module's failure to validate the SAML response signature. An attacker can send an unsigned or incorrectly signed SAML response to a target application configured for single sign-on. This bypass allows the attacker to hijack an existing user session without authentication, potentially granting full access to the victim's account. The weakness is classified as CWE-347, indicating improper signature validation.

Affected Systems

Siemens' Mendix SAML module for Mendix 10 compatible (all versions below 4.2.3), Mendix 11 compatible (also below 4.2.3), and Mendix 9.24 compatible (below 3.6.27) are affected. These modules are used to integrate SAML-based single sign-on into Mendix applications, and the vulnerability applies to any installation still running the specified legacy versions.

Risk and Exploitability

The CVSS score of 8.8 places this issue in the high severity range, and the lack of an EPSS score means the exploitation probability is uncertain. Because the flaw allows unauthenticated remote attackers to hijack sessions, it is potentially exploitable in environments where SAML responses are received from trusted identity providers but not properly validated. The vulnerability is not yet listed in CISA's KEV database, indicating no public exploit samples are known, but the high severity warrants active monitoring.

Generated by OpenCVE AI on September 3, 2026 at 12:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Mendix SAML module to version 4.2.3 or later for Mendix 10 and 11 compatible releases, and to version 3.6.27 or later for Mendix 9.24 compatible releases.
  • Enable strict signature enforcement in the SAML configuration to ensure all responses are validated before authentication.
  • If an upgrade cannot be performed immediately, restrict SAML traffic to trusted identity providers, apply network segmentation, and monitor authentication logs for anomalous session hijacking attempts.

Generated by OpenCVE AI on September 3, 2026 at 12:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens mendix Saml (mendix 10 Compatible)
Siemens mendix Saml (mendix 11 Compatible)
Siemens mendix Saml (mendix 9.24 Compatible)
Vendors & Products Siemens
Siemens mendix Saml (mendix 10 Compatible)
Siemens mendix Saml (mendix 11 Compatible)
Siemens mendix Saml (mendix 9.24 Compatible)

Thu, 03 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Mendix SAML Module Fails to Validate SAML Response Signature, Allowing Session Hijacking

Thu, 03 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations.
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Siemens Mendix Saml (mendix 10 Compatible) Mendix Saml (mendix 11 Compatible) Mendix Saml (mendix 9.24 Compatible)
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-09-03T18:15:38.743Z

Reserved: 2026-08-26T12:49:28.232Z

Link: CVE-2026-80465

cve-icon Vulnrichment

Updated: 2026-09-03T18:15:33.754Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T13:06:10.877

Modified: 2026-09-08T18:41:55.127

Link: CVE-2026-80465

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:33:15Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature