{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mendix-saml-mendix-9.24-compatible--v3.6.27/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mendix:saml:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.7,"id":"CVE-2026-80465"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Mendix SAML (Mendix 10 compatible) (\u003c V4.2.3)","Mendix SAML (Mendix 11 compatible) (\u003c V4.2.3)","Mendix SAML (Mendix 9.24 compatible) (\u003c V3.6.27)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","authentication-bypass","sso","mendix"],"_cs_type":"advisory","_cs_vendors":["Mendix"],"content_html":"\u003cp\u003eCVE-2026-80465 is a critical authentication bypass vulnerability affecting specific versions of the Mendix SAML module. The vulnerability stems from the module's failure to properly validate SAML response signatures. By exploiting this flaw, unauthenticated remote attackers can forge or manipulate SAML assertions, potentially gaining unauthorized access to user sessions within Single Sign-On (SSO) environments. This vulnerability impacts several compatibility versions of the module, specifically Mendix SAML (Mendix 10 compatible) versions prior to 4.2.3, Mendix SAML (Mendix 11 compatible) versions prior to 4.2.3, and Mendix SAML (Mendix 9.24 compatible) versions prior to 3.6.27. Defenders should prioritize patching, as successful exploitation results in complete account takeover for affected SSO configurations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to bypass authentication and hijack active user sessions. The impact is significant for organizations relying on Mendix-based SSO, potentially exposing internal applications to unauthorized access. Given the nature of authentication bypasses, the risk of broad lateral movement and unauthorized data access is high.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of the Mendix SAML module to the secure versions specified by the vendor: upgrade Mendix SAML (Mendix 10 compatible) and (Mendix 11 compatible) to V4.2.3 or later, and Mendix SAML (Mendix 9.24 compatible) to V3.6.27 or later. Since no specific IOCs are available, SOC teams should audit authentication logs for anomalous SAML assertion patterns or unauthorized session initiation events originating from untrusted network segments.\u003c/p\u003e\n","date_modified":"2026-09-03T13:21:28Z","date_published":"2026-09-03T13:21:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mendix-saml-bypass/","summary":"An authentication bypass vulnerability (CVE-2026-80465) in multiple Mendix SAML module versions allows unauthenticated attackers to hijack user sessions via improper SAML response signature validation.","title":"Authentication Bypass in Mendix SAML Module","url":"https://feed.craftedsignal.io/briefs/2026-09-mendix-saml-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Mendix SAML (Mendix 9.24 Compatible) (\u003c V3.6.27)","version":"https://jsonfeed.org/version/1.1"}