Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-7557: Progress MarkLogic Server SAML Bypass Vulnerability
CVE-2026-7557
CVE-2026-7557
Summary
Progress MarkLogic Server versions 11.3.6 and earlier, and 12.0.3 and earlier, have a security issue with their SAML authentication module. An attacker can bypass authentication and pretend to be any user, including administrators, if SAML single sign-on is enabled. Update to version 11.3.6 or later, or version 12.0.3 or later, to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| progress software corporation | marklogic server | < 11.3.6 |
Original title
SAML authentication bypass in Progress MarkLogic Server
Original description
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
nvd CVSS3.1
9.1
Vulnerability type
CWE-347
Improper Verification of Cryptographic Signature
Published: 5 Aug 2026 · Updated: 5 Aug 2026 · First seen: 5 Aug 2026