SAML Response Signature Validation Issue in Mendix Products
CVE-2026-80465
8.8HIGH
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 3 September 2026
What is CVE-2026-80465?
A vulnerability exists in the Mendix SAML implementation across several product versions, which fails to adequately validate the SAML response signature. This oversight may enable unauthenticated remote attackers to exploit specific single sign-on (SSO) configurations, potentially hijacking user sessions and gaining unauthorized access to sensitive information.
Affected Version(s)
Mendix SAML (Mendix 10 compatible) 0
Mendix SAML (Mendix 11 compatible) 0
Mendix SAML (Mendix 9.24 compatible) 0