CVE-2026-7557: SAML authentication bypass in Progress MarkLogic Server
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress MarkLogic Serverto a version that resolves this vulnerability.Fixed in 11.3.6 - Upgrade
Upgrade
Progress MarkLogic Serverto a version that resolves this vulnerability.Fixed in 12.0.3 - Configuration
If SAML single sign-on is not required, disable SAML authentication/bypass paths by turning off SAML SSO in Progress MarkLogic Server until upgraded to versions that are not affected.
Progress MarkLogic Server (SAML SSO) SAML single sign-on = disabled