Government Advisory

Siemens Mendix SAML Flaw Could Let Attackers Hijack Login Sessions

CISA · 15 Sept 2026
Key Takeaway If your business uses Mendix applications with SAML single sign-on, update the SAML module to the latest fixed version as soon as possible.

Siemens has issued a security advisory for its Mendix SAML module, a component used to enable single sign-on (SSO) in applications built on the Mendix low-code platform. The vulnerability, rated 8.7 out of 10 in severity, occurs because affected versions fail to properly verify the cryptographic signature on SAML responses. This weakness could let an unauthenticated remote attacker hijack a user's session in specific SSO configurations, potentially gaining access to accounts without needing valid credentials.

The issue affects Mendix SAML versions compatible with Mendix 9.24, 10 and 11 prior to fixed releases (3.6.27 and 4.2.3 respectively). Mendix has released updated versions and recommends all users upgrade immediately. The advisory is relevant to organisations in critical manufacturing and IT sectors worldwide, and any Australian business using Mendix-built applications with SAML-based SSO should check their exposure.

While Mendix is a specialised low-code development platform rather than mainstream consumer software, it is widely used by enterprises and government agencies to build custom business applications, making this a meaningful risk for organisations that rely on it.

Siemens Mendix SAML SSO vulnerability

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.