VDB

CVE-2025-40758

CVE-2025-40758 PUBLISHED CVSS 8.699999809265137 HIGH

A vulnerability has been identified in Mendix SAML (Mendix 10.12 compatible) (All versions < V4.0.3), Mendix SAML (Mendix 10.21 compatible) (All versions < V4.1.2), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.21). Affected versions of the module insufficiently enforce signature validation and binding checks. This could allow unauthenticated remote attackers to hijack an account in specific SSO configurations.

EPSS 0.02% · 6.0th percentile

Risk Scores

CVSS v3.1
8.699999809265137
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
EPSS Score
0.02%
6.0th percentile

Affected Products

VendorProductVersions
SiemensMendix SAML (Mendix 9.24 compatible)0
SiemensMendix SAML (Mendix 10.12 compatible)0
SiemensMendix SAML (Mendix 10.21 compatible)0

Timeline

  • Aug 14, 2025 Coalition ESS Score
  • Aug 14, 2025 CVE Published
  • Aug 14, 2025 CVE Updated
  • Aug 14, 2025 PoC Published
  • Aug 15, 2025 EPSS Score
  • Aug 15, 2025 Coalition ESS Score
  • Aug 19, 2025 PoC Published
  • Aug 19, 2025 PoC Published
  • Aug 22, 2025 Coalition ESS Score
  • Aug 23, 2025 EPSS Score
  • Aug 26, 2025 Coalition ESS Score
  • Aug 31, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›