Siemens (Mendix SAML Module) Product Security Update Advisory
Overview
Siemens has released a security update addressing a vulnerability in the Mendix SAML module. This vulnerability stems from insufficient verification of SAML response signatures and could lead to account compromise.
Affected Products
- Mendix SAML (Mendix 10 compatible) versions prior to V4.2.3.
- Mendix SAML (Mendix 11 compatible) versions prior to V4.2.3.
- Mendix SAML (Mendix 9.24 Compatible) versions prior to V3.6.27.
Vulnerability Information
- CVE-2026-80465.
- CVSS 8.7.
- The vulnerability involves account takeover due to insufficient verification of SAML response signatures in the Mendix SAML module.
Resolution
A Vulnerability Patch was released in an update on September 3, 2026. Siemens has advised affected users to update to the following versions:
- Mendix SAML (Mendix 10 compatible) V4.2.3 And later.
- Mendix SAML (Mendix 11 compatible) V4.2.3 And later.
- Mendix SAML (Mendix 9.24 Compatible) V3.6.27 And later.
Reference
Details regarding this vulnerability are provided in the document SSA-887643 V1.0: Account Hijacking Vulnerability in Mendix SAML Module.