Machine-generated analysis · WAYSCloud LLM
Versions of Siemens Mendix SAML earlier than 4.2.3 (Mendix 10/11) or 3.6.27 (Mendix 9.24) are vulnerable to CVE-2026-80465. The flaw allows unauthenticated remote attackers to hijack a user session in specific SSO configurations.
Context
The advisory concerns the Siemens Mendix SAML module, a component that provides SAML-based single sign-on for Mendix applications. The module does not correctly validate SAML response signatures, which could let unauthenticated remote attackers hijack an account session in certain SSO configurations. The advisory notes the module is deployed worldwide, including in manufacturing and information technology sectors.
Operator considerations
Check: inventory Mendix SAML module versions and identify any installations running versions earlier than 4.2.3 (Mendix 10/11) or 3.6.27 (Mendix 9.24).
Isolate: segment or restrict SAML authentication traffic until the module is updated.
Patch: apply the vendor-provided update to version 4.2.3 or later (or 3.6.27 or later for Mendix 9.24).
Log: monitor authentication logs for unexpected session creations or SAML processing errors.
Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.
The following versions of Siemens Mendix SAML are affected:
Mendix SAML (Mendix 10 compatible) vers:intdot/
Read the full advisory on CISA →