Junglewise Threat Intelligence

CVE-2026-7557: Progress MarkLogic Server SAML signature verification bypass

CVE-2026-7557 · Severity: critical · CVSS 9.1 · Published 2026-08-05

Technologies: Progress Marklogic Server. Vendors: Progress.

Executive brief

Progress MarkLogic Server is a NoSQL database platform commonly used for enterprise content management and analytics. When SAML single sign-on is enabled, an improper cryptographic signature verification flaw allows unauthenticated remote attackers to bypass authentication and impersonate any user, including system administrators. This enables attackers to gain complete unauthorized access to sensitive data and database operations without valid credentials.

Technical details

This vulnerability is a cryptographic signature verification bypass in the SAML authentication module. The root cause is improper validation of SAML cryptographic signatures, which allows an unauthenticated remote attacker to forge or bypass SAML assertions without valid authentication. The attack requires network access to a MarkLogic Server deployment configured with SAML SSO enabled, but no prior authentication is necessary. A successful exploit permits the attacker to assume the identity of arbitrary users, including administrators, granting full database access. Patches are available in versions 11.3.6 and 12.0.3 or later.

Affected products

  • Progress MarkLogic Server before 11.3.6 and 12.0.3

Timeline

  • 2026-08-05: disclosed

References

Related threats