Progress
Progress Marklogic Server: vulnerabilidades y CVE
Progress Marklogic Server tiene 10 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses10
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-9203 | Alta (8.5) | 0.34% | — | 5 ago 2026 | A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints.… |
| CVE-2026-9195 | Crítica (9.3) | 0.65% | — | 5 ago 2026 | A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary… |
| CVE-2026-9193 | Crítica (9.9) | 0.46% | — | 5 ago 2026 | An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and… |
| CVE-2026-9192 | Crítica (9.8) | 0.83% | — | 5 ago 2026 | An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the… |
| CVE-2026-9190 | Crítica (9.1) | 0.74% | — | 5 ago 2026 | An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's… |
| CVE-2026-8709 | Crítica (9.9) | 0.46% | — | 5 ago 2026 | An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate… |
| CVE-2026-7557 | Crítica (9.1) | 0.46% | — | 5 ago 2026 | An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass… |
| CVE-2026-7329 | Crítica (9.9) | 0.57% | — | 5 ago 2026 | An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to… |
| CVE-2026-7327 | Alta (8.1) | 0.39% | — | 5 ago 2026 | An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate… |
| CVE-2026-7326 | Alta (8.8) | 0.21% | — | 5 ago 2026 | A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.