CVE-2026-80465
Last modified
CVE-2026-80465 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Mendix SAML (Mendix 10 compatible) | < V4.2.3 |
| Siemens | Mendix SAML (Mendix 11 compatible) | < V4.2.3 |
| Siemens | Mendix SAML (Mendix 9.24 compatible) | < V3.6.27 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-80465?
How severe is CVE-2026-80465?
How do I fix CVE-2026-80465?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80439The Redirection for Contact Form 7 WordPress plugin from 2.2…4.8
- CVE-2026-8044CWE-88: Improper Neutralization of Argument Delimiters in a …8.6
- CVE-2026-80440The Hustle WordPress plugin before 7.8.14.2 does not prevent…4.8
- CVE-2026-8045CWE-611 Improper Restriction of XML External Entity Referenc…6.5
- CVE-2026-8046The affected products insufficiently verify authorization wh…8.1
- CVE-2026-80462A vulnerability in the Chef Automate API gateway and identit…10
- CVE-2026-80467The Advanced Custom Fields: Extended WordPress plugin before…8.1
- CVE-2026-80469An attacker may achieve arbitrary code execution on a target…8.3
- CVE-2026-8047The affected products perform improper length checking when …8.7
- CVE-2026-8048The My Email Shortcode plugin for WordPress is vulnerable to…6.4
- CVE-2026-80488The WP Ultimate CSV Importer WordPress plugin before 9.0 do…4.1
- CVE-2026-80489Converting crafted EUC_JISX0213 input to UCS-4 or the intern…5.9
Are you affected by CVE-2026-80465?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
