Improper SAML Signature Validation in Mendix SAML Module Enables Account Hijacking
AI analysis
CVE-2026-80465 is a cryptographic signature verification flaw (CWE-347) in the Mendix SAML single sign-on module, which fails to properly validate the signature on SAML responses it receives. An unauthenticated remote attacker can trigger it by submitting a crafted SAML response during the SSO login flow, and exploitation is limited to specific SAML SSO configurations (reflected in the High attack complexity and 'Previous attack requirements' in the 8.8 High CVSS 4.0 score). A successful attack allows the attacker to hijack a user account or session, with high confidentiality and integrity impact. Organizations running Mendix applications built on Mendix 9.24, 10, or 11 that use affected versions of the SAML module with SAML-based SSO are affected. There is currently no known public proof-of-concept, no CISA KEV listing, and a low 0.2% EPSS probability, indicating no observed or publicly demonstrated exploitation.
What to do: Upgrade the Mendix SAML module to V4.2.3 or later for Mendix 10- and 11-compatible apps, and to V3.6.27 or later for Mendix 9.24-compatible apps. Inventory which applications use the SAML module and review their SSO configuration, since only specific SAML SSO setups are exploitable. Although no public PoC or in-the-wild exploitation is known, patch promptly given the high CVSS 4.0 rating and the typical severity of SAML signature bypass flaws.
Affected
| Siemens (Mendix) Mendix SAML (Mendix 11 compatible) | All versions < V4.2.3 |
| Siemens (Mendix) Mendix SAML (Mendix 10 compatible) | All versions < V4.2.3 |
| Siemens (Mendix) Mendix SAML (Mendix 9.24 compatible) | All versions < V3.6.27 |
Estimated exposure
largetens of thousands of Mendix app deployments with the SAML SSO module active (estimated) — Estimated from Mendix's broad enterprise low-code install base (Siemens-owned, thousands of enterprise customers) and the SAML module being the standard enterprise IdP integration, noting that only a subset using the specific vulnerable…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations.