← Back to Feed
Siemens Mendix SAML
CVE-2026-80465
September 15, 2026 · CISA (US-CERT) · Severity: CRITICAL
The Mendix SAML module contains a vulnerability tracked as CVE-2026-80465 that could allow unauthenticated remote attackers to hijack user accounts in specific SSO configurations. The flaw affects Mendix SAML versions prior to 4.2.3 for Mendix 10 and 11 compatibility, and versions prior to 3.6.27 for Mendix 9.24 compatibility. Mendix has provided fix releases and recommends updating to the latest version to remediate the account hijacking risk. As a general security practice, organizations should apply updates promptly.
Key Takeaways
- Siemens Mendix SAML module contains a vulnerability allowing unauthenticated remote attackers to hijack accounts in specific SSO configurations.
- The flaw affects multiple Mendix compatibility versions, with fixes available in SAML module version 4.2.3 for Mendix 10 and 11, and 3.6.27 for Mendix 9.24.
- Organizations using Mendix SAML for single sign-on should update immediately to prevent potential account takeover attacks via this vulnerability.