External risk intelligence

Progress MarkLogic Server SAML Authentication Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-7557

The vulnerability resides in the SAML authentication module of a database server. SAML is an identity protocol designed for authentication, which, when enabled, typically exposes an interface to the internet or an extranet to facilitate single sign-on for users and services. Because it handles identity and authentication, it is functionally required to be reachable to fulfill its purpose.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An improper verification of cryptographic signature in Progress MarkLogic Server's SAML authentication module could allow an unauthenticated attacker to impersonate any user, including administrators, if single sign-on is enabled. This presents a significant risk to authentication integrity for affected deployments.

  • Unauthenticated attackers can impersonate users.
  • It impacts authentication and user access.
  • Confirm if SAML SSO is enabled and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by targeting the SAML authentication module of Progress MarkLogic Server, specifically in deployments where single sign-on is enabled. By crafting a malicious SAML request, an unauthenticated remote attacker can bypass the normal authentication process. This allows them to impersonate any user, including administrators, gaining unauthorized access to the system and its data.

  • Unauthenticated remote network access required.
  • Crafted SAML request triggers bypass.
  • Risk of unauthorized administrative access.

Live Threat

Current exploitation, exposure, and threat context

An improper verification of cryptographic signature in Progress MarkLogic Server's SAML module could allow an unauthenticated attacker to impersonate any user, including administrators, when SAML single sign-on is enabled. This could lead to unauthorized access to system data and user information.

  • Access to sensitive system and user data.
  • Bypassing authentication via network.
  • Unauthorized administrative control.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Progress MarkLogic Server's SAML module requires immediate attention from teams managing identity and access, likely encompassing platform, infrastructure, and security operations. The first practical step is to identify all MarkLogic Server instances where SAML authentication is enabled, assess their external reachability and business criticality, and then determine the accountable system owner to plan remediation during the next maintenance window or coordinate with the vendor for a timely fix.

  • Platform or infrastructure teams own the issue.
  • Verify SAML enablement and external reachability.
  • Plan vendor-coordinated remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Progress MarkLogic Server?

Progress MarkLogic Server is a multi-model database platform designed to store, manage, and search complex, unstructured data at scale. It is frequently used by large enterprises to power data integration hubs, content management systems, and high-performance analytical applications that require reliable access control and identity management.

What does CVE-2026-7557 mean?

This vulnerability is an improper verification of cryptographic signature, classified as CWE-347. In plain English, the system fails to correctly validate the digital "seal" on authentication tokens. Because the server does not properly check if these tokens are authentic, an attacker can forge them to masquerade as any user, even an administrator, without ever needing a valid password.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted SAML request to the server's authentication module. It is important to note that this flaw does not affect MarkLogic instances that use local database authentication or other login methods; the vulnerability is only present when SAML single sign-on (SSO) is explicitly enabled.

Why is this considered a relevant threat?

According to Halo Surface Signal, this issue is critical because SAML is an identity protocol that typically requires internet or extranet reachability to function for users and services. Because the vulnerable module is essentially designed to be accessible to facilitate logins, the barrier for an attacker to reach and interact with this service is low.

How do I respond if I use MarkLogic?

Start by identifying every instance of MarkLogic Server in your environment where SAML single sign-on is currently active. Once you have a list of these specific systems, coordinate with the system owners to assess their external visibility and prepare for vendor-supplied patches, prioritizing those that are reachable from outside your private network.

References