← All CVEs

CVE-2026-7557

critical · 9.1

An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.

9.1
CVSS
0.3%
EPSS (exploit prob.)
25th
EPSS percentile
2026-08-05
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-347

Affected products

VendorProductAffected versions
progressmarklogic_server< 11.3.6
progressmarklogic_server>= 12.0.0, < 12.0.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-7557