VYPR
advisoryPublished Sep 15, 2026· 1 source

Siemens Mendix SAML Module Vulnerable to Account Hijacking

A critical vulnerability in Siemens' Mendix SAML module could allow unauthenticated attackers to hijack user accounts through session hijacking in specific Single Sign-On configurations.

Siemens has issued a critical security advisory detailing a vulnerability within its Mendix SAML module that could lead to unauthorized account takeover. The flaw, identified as CVE-2026-80465, stems from an improper verification of cryptographic signatures within the SAML response process. This weakness allows unauthenticated remote attackers to potentially hijack user sessions, effectively gaining control of accounts in specific Single Sign-On (SSO) configurations.

The vulnerability affects multiple versions of the Mendix SAML module, specifically those compatible with Mendix versions 9.24, 10, and 11. For Mendix 9.24, versions prior to 3.6.27 are vulnerable. For Mendix 10 and 11, versions earlier than 4.2.3 are impacted. The Common Vulnerability Scoring System (CVSS) v3.1 base score for this vulnerability is rated at a critical 8.7, highlighting the severity of the potential impact.

Exploitation of CVE-2026-80465 relies on an attacker's ability to manipulate SAML responses. By crafting a malicious SAML response that bypasses signature validation, an attacker could trick the application into accepting a forged authentication assertion. This would allow them to impersonate a legitimate user and hijack their active session, granting them access to the user's account and associated data or functionalities within the Mendix application.

The potential impact is significant, particularly in environments where Mendix applications are used for critical business processes or manage sensitive data. Account hijacking can lead to data breaches, unauthorized system modifications, financial fraud, and reputational damage. The advisory notes that the vulnerability is present in configurations deployed worldwide, affecting critical manufacturing and information technology sectors.

Siemens has addressed this vulnerability by releasing updated versions of the Mendix SAML module. Users are strongly advised to update to the latest versions: 3.6.27 or later for Mendix 9.24 compatibility, and 4.2.3 or later for Mendix 10 and 11 compatibility. These updates are available through the Mendix Marketplace.

In addition to applying the vendor-provided patches, general security recommendations from CISA and Siemens should be followed. These include minimizing network exposure for control system devices, isolating them from business networks, and using secure remote access methods like VPNs. Organizations should also implement defense-in-depth strategies and conduct thorough impact and risk assessments before deploying any defensive measures.

This vulnerability was reported to CISA by Siemens ProductCERT. Siemens has provided detailed advisories (SSA-887643) in both HTML and CSAF formats, which offer further technical details and remediation guidance. The CISA advisory serves to increase the visibility of this critical flaw within the industrial control systems community.

Synthesized by Vypr AI