CVE-2026-7557
marklogic_server: Improper Verification of Cryptographic Signature (CVE-2026-7557)
criticalEPSS 0.5%
Affected
- progress/marklogic_server
lt *..11.3.6 - progress/marklogic_server
between 12.0.0..12.0.3
Description
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
Source: NVD (NIST)cvelistv5
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
progressmarklogic_server
12.0.0 – 12.0.311.3.6fixed from 11.3.6Metrics
Show all metrics
Severity
critical
81.43
no public PoC known
9.1
Published
2026-08-05 15:33 UTC
CWE-347
Weakness classes (CWE)
CWE-347Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-09-03 14:06 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:* versions up to (excluding) 11.3.6 *cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:* versions from (including) 12.0.0 up to (excluding) 12.0.3
- Reference Type: Progress Software Corporation: https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026 Types: Vendor Advisory
- CVE Modified2026-08-07 05:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-7557","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI… → {"id":"CVE-2026-7557","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI…
- CVE Modified2026-08-05 19:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-7557","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI…
- New CVE Received2026-08-05 16:17 UTC· security@progress.com
- Affected: MarkLogic Server
- Description: An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- CWE: CWE-347