An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progress Software Corporation
Progress Software Corporation marklogic Server |
|
| Vendors & Products |
Progress Software Corporation
Progress Software Corporation marklogic Server |
Wed, 05 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled. | |
| Title | SAML authentication bypass in Progress MarkLogic Server | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ProgressSoftware
Published: 2026-08-05T15:33:05.872Z
Updated: 2026-08-07T03:55:26.318Z
Reserved: 2026-04-30T19:27:17.815Z
Link: CVE-2026-7557
Updated: 2026-08-05T18:14:46.701Z
No data.
No data.