An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
References
| Link | Resource |
|---|---|
| https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-05 16:17
Updated : 2026-09-03 14:06
NVD link : CVE-2026-7557
Mitre link : CVE-2026-7557
CVE.ORG link : CVE-2026-7557
JSON object : View
Products Affected
progress
- marklogic_server
CWE
CWE-347
Improper Verification of Cryptographic Signature
