CVE-2026-7557

EUVD-2026-53424
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 24.83%
Affected Products (NVD)
VendorProductVersion
progressmarklogic_server
𝑥
< 11.3.6
progressmarklogic_server
12.0.0 ≤
𝑥
< 12.0.3
𝑥
= Vulnerable software versions