Skip to content
SiemensCVE-2026-80465

Siemens Mendix SAML (Mendix: improper signature check

High8.8CVE-2026-80465 · Published Sep 3, 2026 · updated Sep 8, 2026

A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations.

Siemens advisory

Affected versions

PackageAffectedFixed in
Mendix SAML (Mendix 10 compatible)
Product
< V4.2.3V4.2.3
Mendix SAML (Mendix 11 compatible)
Product
< V4.2.3V4.2.3
Mendix SAML (Mendix 9.24 compatible)
Product
< V3.6.27V3.6.27
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-347

More Siemens advisories

All Siemens
Advisory
Siemens Reyrolle 7SR5: out-of-bounds write
High8.7Sep 8
Siemens Reyrolle 7SR5: unauthenticated remote attacker could more easily predict
Critical9.3Sep 8
Siemens Reyrolle 7SR5: authentication bypass
Critical9.1Sep 8
Siemens Reyrolle 7SR5: authentication bypass
Critical9.3Sep 8
Siemens Siveillance Control Pro: arbitrary file upload
High8.9Sep 8
Siemens Desigo CC: code execution
High8.6Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.