Executive Summary

CVE-2026-80465 is an improper signature validation flaw in the Mendix SAML single sign-on modules that allows an unauthenticated remote attacker to forge or replay a SAML response and take over an authenticated session under specific SSO configurations. Where a Mendix application fronts operational dashboards, work order systems, or engineering portals connected to plant infrastructure, a hijacked session becomes an authenticated foothold into environments that were never designed to withstand a broken trust boundary.

Technical Exposure Breakdown

SAML security rests entirely on the service provider validating the cryptographic signature on the identity provider assertion. When that validation is incomplete or bypassable, the entire authentication model collapses. According to the grounding data, the affected Mendix SAML modules do not properly validate the SAML response signature, which opens the door to the classic failure classes in this space: acceptance of unsigned assertions, signature wrapping where a valid signature is scoped to a fragment while attacker controlled data sits outside it, or acceptance of a self signed or mismatched signing certificate.

The grounding data specifies that exploitation applies to specific SSO configurations. That qualifier matters for scoping. Not every Mendix SAML deployment will present the vulnerable path, and the exposure depends on how the module is configured to consume and verify assertions. The attack vector is remote and requires no prior authentication, which is consistent with the CVSS score of 8.7 recorded in the grounding data. An attacker who can reach the SAML assertion consumer endpoint and understands the target trust chain can attempt session hijack without valid credentials.

Patch status is listed as unknown in the grounding data, so operators should not assume a fixed build is available and validated for their platform version. Treat the exposure as active until a specific fixed version is confirmed against your deployment.

OT Impact and Compliance Risk

Low code platforms like Mendix increasingly sit in the operational middle layer. They host maintenance interfaces, asset management front ends, operator dashboards, and integration glue that reaches into historians and control system data stores. An authentication bypass on that layer is not a contained IT event. It is a bypass of the identity control that IT and OT teams jointly rely on to gate access.

Under IEC 62443, this directly undermines the identification and authentication control requirements in the SR 1 family, and it degrades the effectiveness of zone and conduit segmentation because the compromised session inherits legitimate authorization. For utilities in scope for NERC CIP, a session hijack against a system supporting BES cyber assets challenges CIP-005 electronic access controls and CIP-007 account management assumptions. Pipeline operators governed by TSA Security Directive SD-02C should map any Mendix fronted access into their access control and segmentation requirements, since a bypassed SSO defeats the policy enforcement point. Water and wastewater utilities operating under AWIA 2018 obligations face the same core problem: the identity layer they attest to is no longer trustworthy where this configuration is present.

Compensating Controls

Do not treat active vulnerability scanning as a safe discovery method here. Probing SAML consumer endpoints on production OT adjacent systems can disrupt session state and, on fragile industrial components downstream, active scanning can brick equipment. Enumerate exposure through configuration review and passive traffic inspection instead.

Confirm a specific fixed module version against your exact Mendix platform build before assuming remediation, and revalidate the SSO configuration afterward rather than trusting the upgrade alone.

BreachSpider Intel

BreachSpider tracks CVE-2026-80465 and related authentication bypass exposure across OT adjacent platforms so operators can monitor affected components and compensating control status in one place.