Account Hijacking Vulnerability in Mendix SAML module
Plan PatchCVSS 8.7SSA-887643Sep 3, 2026
Siemens
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary
The Mendix SAML module contains a vulnerability in SAML assertion validation that allows unauthenticated remote attackers to hijack user accounts when specific SSO configurations are in use. An attacker can bypass signature verification and impersonate legitimate users without valid credentials, gaining unauthorized access to Mendix applications.
What this means
What could happen
An unauthenticated attacker could hijack user accounts in Mendix applications that use SAML for single sign-on authentication, potentially gaining unauthorized access to sensitive operational data and applications.
Who's at risk
Water utilities and municipal electric operators using Mendix-based applications for SCADA data management, billing systems, or control interfaces that rely on SAML-based single sign-on authentication. Affects any Mendix application in operational environments that uses the vulnerable SAML module versions.
How it could be exploited
An attacker sends a specially crafted SAML authentication request to exploit a flaw in how the Mendix SAML module validates SAML assertions. By bypassing proper signature verification in specific SSO configurations, the attacker can impersonate a legitimate user without valid credentials.
Prerequisites
- Mendix application deployed with SAML module for single sign-on authentication
- Network access to the Mendix application's SAML authentication endpoint
- SAML configuration must use a specific vulnerable configuration pattern
remotely exploitableno authentication requiredaccount hijacking enables unauthorized system accessaffects SSO authentication security
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (3)
3 with fix
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDReview SAML authentication logs and user access records for any unauthorized account access or anomalous login activity since the module deployment
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
Mendix SAML (Mendix 9.24 compatible) < V3.6.27
HOTFIXUpdate Mendix SAML module to version 3.6.27 or later (for Mendix 9.24 compatible module)
All products
HOTFIXUpdate Mendix SAML module to version 4.2.3 or later (for Mendix 10 and 11 compatible modules)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/efe54c08-2af4-4478-a0d2-5ea8b560cc83Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.