Siemens Product Security Update Advisory (CVE-2025-40758)

Siemens Product Security Update Advisory (CVE-2025-40758)

Overview

 

We have released a security update to fix vulnerabilities in Siemens products. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2025-40758

 

Mendix SAML Version: Before V3.6.21
Mendix SAML Version: Before V4.0.3
Mendix SAML version: below V4.1.2

 

 

Resolved Vulnerabilities

 

Account hijacking vulnerability in the Mendix SAML module (CVE-2025-40758)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2025-40758

 

Mendix SAML Version: V3.6.21 or later
Mendix SAML Version: V4.0.3 or later
Mendix SAML Version: V4.1.2 and later

 

 

References

 

[1] SSA-395458: Account Hijacking Vulnerability in Mendix SAML Module
https://cert-portal.siemens.com/productcert/html/ssa-395458.html