PatchSiren cyber security CVE debrief
CVE-2026-7557 Progress Software Corporation CVE debrief
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled. The CVE record was published on 2026-08-05T16:17:09.437Z and has not been modified since then. Progress MarkLogic Server administrators and users with SAML single sign-on enabled deployments should verify their authentication module configuration.
- Vendor
- Progress Software Corporation
- Product
- MarkLogic Server
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-05
- Original CVE updated
- 2026-08-05
- Advisory published
- 2026-08-05
- Advisory updated
- 2026-08-05
Who should care
Progress MarkLogic Server administrators and users with SAML single sign-on enabled deployments should prioritize verification of their authentication module and consider immediate action to mitigate potential authentication bypass. This includes reviewing authentication module configuration for SAML single sign-on and considering disabling SAML single sign-on if not required. Additionally, operators and security teams responsible for managing Progress MarkLogic Server deployments should be aware of the vulnerability and take necessary actions to protect their systems. Platform and vulnerability-management teams should also review the vulnerability and plan for necessary updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions, retesting of remediated assets, and closing the item only after evidence is documented are also important considerations. Asset inventory and source tracking can help with these efforts. Rollback/change windows may be necessary for some deployments. Overall, a coordinated effort is required to address this vulnerability effectively across the organization. Security teams should work closely with IT operations to ensure that all necessary steps are taken to mitigate the vulnerability and protect Progress MarkLogic Server deployments with SAML single sign-on enabled. This may involve verifying affected product or component, vulnerability class, likely operational impact, source-confidence limits, and review context. It is essential to have a thorough understanding of the vulnerability and its potential impact on the organization to take appropriate measures to protect against it. The CVE record indicates an improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3. This allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. The vulnerability affects deployments
Technical summary
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled. The vulnerability has a CVSS score of 9.1 and is considered CRITICAL. Progress MarkLogic Server deployments with SAML single sign-on enabled should prioritize verification of their authentication module and consider immediate action to mitigate potential authentication bypass.
Defensive priority
Progress MarkLogic Server deployments with SAML single sign-on enabled should prioritize verification of their authentication module and consider immediate action to mitigate potential authentication bypass.
Recommended defensive actions
- Verify Progress MarkLogic Server version and apply patches 11.3.6 or 12.0.3 if SAML single sign-on is enabled
- Review authentication module configuration for SAML single sign-on
- Consider disabling SAML single sign-on if not required
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record indicates an improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3. This allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. The vulnerability affects deployments with SAML single sign-on enabled.
Official resources
-
CVE-2026-7557 CVE record
CVE.org
-
CVE-2026-7557 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T16:17:09.437Z and has not been modified since then.