Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
If SAML single sign-on is not required, disable it and use local or LDAP authentication until the update can be applied. Restrict the SAML callback endpoint to known identity-provider networks and monitor authentication logs for anomalous SAML logins.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 05 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled. | |
| Title | SAML authentication bypass in Progress MarkLogic Server | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-08-05T15:33:05.872Z
Reserved: 2026-04-30T19:27:17.815Z
Link: CVE-2026-7557
No data.
No data.
No data.
OpenCVE Enrichment
No data.