Improper Verification of Cryptographic Signature in MarkLogic - CVE-2026-7557
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication and impersonate any user.
The vulnerability exists due to improper verification of cryptographic signature in the SAML authentication module when processing a SAML response. A remote attacker can submit a crafted SAML response to bypass authentication and impersonate any user.
Administrator accounts can also be impersonated.