Siemens Mendix SAML auth bypass scores 8.7
Fourth CISA advisory on this module's SAML assertion path since 2021, the attack surface keeps producing the same class of failure.
TL;DR
CISA published advisory ICSA-26-258-06 for CVE-2026-80465, an improper cryptographic signature verification flaw in Siemens Mendix SAML Module (CVSS 8.7). Unauthenticated remote attackers can hijack accounts in specific SSO configurations. Affected versions: Mendix SAML below 4.2.3 (Mendix 10 and 11 compatible) and below 3.6.27 (Mendix 9.24 compatible). Patches are available through the Mendix Marketplace. The vulnerability hits Critical Manufacturing and IT sectors; deployments worldwide are in scope. CISA's advisory is a verbatim republication of Siemens' own CSAF advisory, no independent CISA assessment accompanies it.
The Mendix SAML module has now appeared in four distinct CISA ICS advisories since 2021, each involving the SAML assertion processing path. CVE-2026-80465 continues the pattern: insufficient signature validation lets an unauthenticated remote attacker hijack an account under certain SSO configurations.
The CVSS vector tells a familiar story, network-accessible (AV:N), no privileges required (PR:N), no user interaction (UI:N), scope-changed (S:C), with high confidentiality and integrity impact. Only the attack complexity rating (AC:H) keeps the base score from crossing 9.0. But "high" complexity in SAML signature bypasses has historically not been a reliable barrier; the 2023 advisory for CVE-2023-25957 scored 9.1 with AC:L.
Siemens' mitigation guidance for CVE-2026-80465 points to updates on the Mendix Marketplace, V4.2.3 for Mendix 10 and 11 compatible tracks, V3.6.27 for the Mendix 9.24 compatible track. No workaround is described for this CVE beyond patching.
The advisory carries CISA's standard republication disclaimer: it's a verbatim conversion of Siemens ProductCERT SSA-887643, published "as-is" with no independent CISA assessment. Organizations with Mendix SAML in SSO configurations should verify their module version against the affected ranges and apply the patched release. For those unable to patch immediately, the general recommendation to minimize network exposure applies, but the attack vector is the SAML endpoint itself, which is inherently network-facing in SSO deployments.
Published ·Deep Fathom