CVE-2026-80465

A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 13:06

Updated : 2026-09-08 18:41


NVD link : CVE-2026-80465

Mitre link : CVE-2026-80465

CVE.ORG link : CVE-2026-80465


JSON object : View

Products Affected

No product.

CWE
CWE-347

Improper Verification of Cryptographic Signature