CVE-2026-7557

Summary

An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.

Affected Software

VendorProductVersion RangeStatus
Progress Software CorporationMarkLogic Server11.0.0 < 11.3.6affected
Progress Software CorporationMarkLogic Server12.0.0 < 12.0.3affected

Weaknesses

  • CWE-347: CWE-347: Improper Verification of Cryptographic Signature

Workarounds

If SAML single sign-on is not required, disable it and use local or LDAP authentication until the update can be applied. Restrict the SAML callback endpoint to known identity-provider networks and monitor authentication logs for anomalous SAML logins.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References