# Siemens Mendix SAML flaw enables account hijack

Published: 2026-09-15 · Severity: routine · Sectors: manufacturing, technology
Canonical: https://vorant.io/reports/0c3e9297-713d-51a2-accb-80b6ae6d771d/siemens-mendix-saml-flaw-enables-account-hijack

> A signature validation flaw in Siemens Mendix SAML module lets unauthenticated attackers hijack accounts in certain SSO setups; patches available.

Siemens ProductCERT disclosed a vulnerability (CVE-2026-80465) in the Mendix SAML module affecting versions used with Mendix 9.24, 10, and 11. The flaw stems from improper verification of the SAML response's cryptographic signature (CWE-347), which could allow an unauthenticated remote attacker to forge or manipulate SAML assertions and hijack a user's session in specific single sign-on (SSO) configurations.

Affected versions are Mendix SAML (Mendix 10/11 compatible) prior to V4.2.3, and Mendix SAML (Mendix 9.24 compatible) prior to V3.6.27. Siemens has released fixed versions and recommends all users update via the Mendix Marketplace. There is no indication in this advisory of active exploitation in the wild; this is a vendor-disclosed vulnerability reported through Siemens ProductCERT and republished by CISA as ICSA-26-258-06 (Siemens SSA-887643).

Defenders using Mendix applications with SAML-based SSO should prioritize upgrading to the fixed versions (V4.2.3+ or V3.6.27+ as applicable), audit SSO configurations for exposure, and apply standard ICS network segmentation practices (isolating control system networks, avoiding direct internet exposure, and using VPNs for remote access) as general defense-in-depth measures.

## Mentioned in this report

- Vulnerabilities: CVE-2026-80465

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-06

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0c3e9297-713d-51a2-accb-80b6ae6d771d/siemens-mendix-saml-flaw-enables-account-hijack.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
