CVE-2026-80465: Siemens Mendix SAML Mendix 10 Compatible

High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations.

Affected products

  • Siemens Mendix SAML Mendix 10 Compatible: before V4.2.3 (fixed in V4.2.3)
  • Siemens Mendix SAML Mendix 11 Compatible: before V4.2.3 (fixed in V4.2.3)
  • Siemens Mendix SAML Mendix 9.24 Compatible: before V3.6.27 (fixed in V3.6.27)

Published 2026-09-03. Last modified 2026-09-08.