Siemens Product Security Update Advisory (CVE-2025-40758)
Overview
We have released a security update to fix vulnerabilities in Siemens products. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2025-40758
Mendix SAML Version: Before V3.6.21
Mendix SAML Version: Before V4.0.3
Mendix SAML version: below V4.1.2
Resolved Vulnerabilities
Account hijacking vulnerability in the Mendix SAML module (CVE-2025-40758)
Vulnerability Patches
Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-40758
Mendix SAML Version: V3.6.21 or later
Mendix SAML Version: V4.0.3 or later
Mendix SAML Version: V4.1.2 and later
References
[1] SSA-395458: Account Hijacking Vulnerability in Mendix SAML Module
https://cert-portal.siemens.com/productcert/html/ssa-395458.html