CVE-2026-7557
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Summary
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progress Software Corporation | MarkLogic Server | 11.0.0 < 11.3.6 | affected |
| Progress Software Corporation | MarkLogic Server | 12.0.0 < 12.0.3 | affected |
Weaknesses
- CWE-347: CWE-347: Improper Verification of Cryptographic Signature
Workarounds
If SAML single sign-on is not required, disable it and use local or LDAP authentication until the update can be applied. Restrict the SAML callback endpoint to known identity-provider networks and monitor authentication logs for anomalous SAML logins.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.