Siemens (Mendix SAML Module) Product Security Update Advisory

Siemens (Mendix SAML Module) Product Security Update Advisory

Overview

Siemens has released a security update addressing a vulnerability in the Mendix SAML module. This vulnerability stems from insufficient verification of SAML response signatures and could lead to account compromise.

Affected Products

  • Mendix SAML (Mendix 10 compatible) versions prior to V4.2.3.
  • Mendix SAML (Mendix 11 compatible) versions prior to V4.2.3.
  • Mendix SAML (Mendix 9.24 Compatible) versions prior to V3.6.27.

Vulnerability Information

  • CVE-2026-80465.
  • CVSS 8.7.
  • The vulnerability involves account takeover due to insufficient verification of SAML response signatures in the Mendix SAML module.

Resolution

A Vulnerability Patch was released in an update on September 3, 2026. Siemens has advised affected users to update to the following versions:

  • Mendix SAML (Mendix 10 compatible) V4.2.3 And later.
  • Mendix SAML (Mendix 11 compatible) V4.2.3 And later.
  • Mendix SAML (Mendix 9.24 Compatible) V3.6.27 And later.

Reference

Details regarding this vulnerability are provided in the document SSA-887643 V1.0: Account Hijacking Vulnerability in Mendix SAML Module.