Cyber Resilience
← All news
Confirmed

Siemens Mendix SAML

Our takeSiemens fixed an account hijack in the Mendix SAML module that lets unauthenticated remote attackers take over sessions in certain SSO setups. Update to the latest version.
Sources (1)
What this means for you — Security leader:Update the Mendix SAML module to version 4 or later immediately if you use it for SSO in Mendix 10 applications; the flaw allows unauthenticated remote account hijacking in specific configurations.
What this means for you — Lean IT orgs:If your team builds apps with Mendix and uses its SAML single sign-on, update the SAML module to the newest version right away.
What this means for you — MSP:Audit all client Mendix 10 environments for the SAML module; update to version 4+ where present, as unauthenticated attackers can hijack accounts in vulnerable SSO setups.
What this means for you — Researcher:Review affected Mendix SAML versions and test your SSO configurations against the account hijacking vector described in ICSA-26-258-06.