CVE-2026-7557

marklogic_server: Improper Verification of Cryptographic Signature (CVE-2026-7557)

criticalEPSS 0.5%

Affected

  • progress/marklogic_server lt *..11.3.6
  • progress/marklogic_server between 12.0.0..12.0.3

Description

An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

progressmarklogic_server
12.0.0 – 12.0.311.3.6fixed from 11.3.6

Metrics

9.1
Source: nvd-v3
38.1 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.5 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-05 15:33 UTC
CWE-347

Weakness classes (CWE)

  • CWE-347Base

    Improper Verification of Cryptographic Signature

    The product does not verify, or incorrectly verifies, the cryptographic signature for data.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-09-03 14:06 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:* versions up to (excluding) 11.3.6 *cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:* versions from (including) 12.0.0 up to (excluding) 12.0.3
    • Reference Type: Progress Software Corporation: https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026 Types: Vendor Advisory
  2. CVE Modified2026-08-07 05:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-7557","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI… → {"id":"CVE-2026-7557","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI…
  3. CVE Modified2026-08-05 19:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-7557","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI…
  4. New CVE Received2026-08-05 16:17 UTC· security@progress.com
    • Affected: MarkLogic Server
    • Description: An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
    • CWE: CWE-347

Linked advisories