<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Mendix - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/mendix/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 13:21:28 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/mendix/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in Mendix SAML Module</title><link>https://feed.craftedsignal.io/briefs/2026-09-mendix-saml-bypass/</link><pubDate>Thu, 03 Sep 2026 13:21:28 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-mendix-saml-bypass/</guid><description>An authentication bypass vulnerability (CVE-2026-80465) in multiple Mendix SAML module versions allows unauthenticated attackers to hijack user sessions via improper SAML response signature validation.</description><content:encoded><![CDATA[<p>CVE-2026-80465 is a critical authentication bypass vulnerability affecting specific versions of the Mendix SAML module. The vulnerability stems from the module's failure to properly validate SAML response signatures. By exploiting this flaw, unauthenticated remote attackers can forge or manipulate SAML assertions, potentially gaining unauthorized access to user sessions within Single Sign-On (SSO) environments. This vulnerability impacts several compatibility versions of the module, specifically Mendix SAML (Mendix 10 compatible) versions prior to 4.2.3, Mendix SAML (Mendix 11 compatible) versions prior to 4.2.3, and Mendix SAML (Mendix 9.24 compatible) versions prior to 3.6.27. Defenders should prioritize patching, as successful exploitation results in complete account takeover for affected SSO configurations.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to bypass authentication and hijack active user sessions. The impact is significant for organizations relying on Mendix-based SSO, potentially exposing internal applications to unauthorized access. Given the nature of authentication bypasses, the risk of broad lateral movement and unauthorized data access is high.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the upgrade of the Mendix SAML module to the secure versions specified by the vendor: upgrade Mendix SAML (Mendix 10 compatible) and (Mendix 11 compatible) to V4.2.3 or later, and Mendix SAML (Mendix 9.24 compatible) to V3.6.27 or later. Since no specific IOCs are available, SOC teams should audit authentication logs for anomalous SAML assertion patterns or unauthorized session initiation events originating from untrusted network segments.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>authentication-bypass</category><category>sso</category><category>mendix</category></item></channel></rss>