AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-7557

CRITICAL · CVSS 9.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

An improper verification of cryptographic signatures in the SAML authentication module of Progress MarkLogic Server allows unauthenticated remote attackers to bypass authentication and impersonate any user, including administrators. This critical vulnerability primarily impacts deployments utilizing SAML single sign-on, posing significant risks to user data and system integrity. Organizations using affected versions should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-7557
Severity
CRITICAL
CVSS
9.1
EPSS
0.27%

Original NVD Description

An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.