Mendix SAML <v4.2.3 Signature Validation Flaw
CVE-2026-80465 Published on September 3, 2026
A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations.
Weakness Type
Improper Verification of Cryptographic Signature
The software does not verify, or incorrectly verifies, the cryptographic signature for data.
Affected Versions
Siemens Mendix SAML (Mendix 10 compatible):- Before V4.2.3 is affected.
- Before V4.2.3 is affected.
- Before V3.6.27 is affected.