CVE-2026-7557 PUBLISHED

SAML authentication bypass in Progress MarkLogic Server

Assigner: ProgressSoftware
Reserved: 30.04.2026 Published: 05.08.2026 Updated: 05.08.2026

An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Score: 9.1

Product Status

Vendor Progress Software Corporation
Product MarkLogic Server
Versions Default: unaffected
  • affected from 11.0.0 to 11.3.6 (excl.)
  • affected from 12.0.0 to 12.0.3 (excl.)

Workarounds

If SAML single sign-on is not required, disable it and use local or LDAP authentication until the update can be applied. Restrict the SAML callback endpoint to known identity-provider networks and monitor authentication logs for anomalous SAML logins.

References

Problem Types

  • CWE-347: Improper Verification of Cryptographic Signature CWE