CVE-2026-7557

An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-05 16:17

Updated : 2026-09-03 14:06


NVD link : CVE-2026-7557

Mitre link : CVE-2026-7557

CVE.ORG link : CVE-2026-7557


JSON object : View

Products Affected

progress

  • marklogic_server
CWE
CWE-347

Improper Verification of Cryptographic Signature