Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
If SAML single sign-on is not required, disable it and use local or LDAP authentication until the update can be applied. Restrict the SAML callback endpoint to known identity-provider networks and monitor authentication logs for anomalous SAML logins.
Wed, 05 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled. | |
| Title | SAML authentication bypass in Progress MarkLogic Server | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-08-05T18:42:22.772Z
Reserved: 2026-04-30T19:27:17.815Z
Link: CVE-2026-7557
Updated: 2026-08-05T18:14:46.701Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T17:45:16Z