CRITICALVulnerability

CVE-2026-7557

An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.

Properties

severity
CRITICAL
score
9.1
cve_id
CVE-2026-7557
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
published_at
2026-08-05T16:17:09.437
last_modified
2026-08-28T21:16:15.740

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Verification of Cryptographic Signature

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-7557 — Ninja Signal Threat Intelligence | Ninja Signal