CVE-2026-7557: SAML authentication bypass in Progress MarkLogic Server
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress MarkLogic Serverto a version that resolves this vulnerability.Fixed in 11.3.6 - Upgrade
Upgrade
Progress MarkLogic Serverto a version that resolves this vulnerability.Fixed in 12.0.3 - Configuration
If SAML single sign-on is not required, disable SAML authentication/bypass paths by turning off SAML SSO in Progress MarkLogic Server until upgraded to versions that are not affected.
Progress MarkLogic Server (SAML SSO) SAML single sign-on = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7557?
The severity of CVE-2026-7557 is critical with a score of 9.1.
How do I fix CVE-2026-7557?
To fix CVE-2026-7557, upgrade Progress MarkLogic Server to version 11.3.6 or 12.0.3 or higher.
What type of vulnerability is CVE-2026-7557?
CVE-2026-7557 is an improper verification of cryptographic signature vulnerability in the SAML authentication module.
Who is affected by CVE-2026-7557?
CVE-2026-7557 affects all versions of Progress MarkLogic Server prior to 11.3.6 and 12.0.3.
What can an attacker do with CVE-2026-7557?
An attacker can exploit CVE-2026-7557 to bypass authentication and impersonate any user, including administrators.