Progress
Progress Marklogic Server: vulnerabilities and CVEs
Progress Marklogic Server has 10 published vulnerabilities, 10 of them in the last 12 months. 7 are rated critical and 0 are listed by CISA as actively exploited.
CVEs10
Last 12 months10
Critical7
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9203 | High (8.5) | 0.34% | — | Aug 5, 2026 | A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints.… |
| CVE-2026-9195 | Critical (9.3) | 0.65% | — | Aug 5, 2026 | A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary… |
| CVE-2026-9193 | Critical (9.9) | 0.46% | — | Aug 5, 2026 | An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and… |
| CVE-2026-9192 | Critical (9.8) | 0.83% | — | Aug 5, 2026 | An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the… |
| CVE-2026-9190 | Critical (9.1) | 0.74% | — | Aug 5, 2026 | An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's… |
| CVE-2026-8709 | Critical (9.9) | 0.46% | — | Aug 5, 2026 | An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate… |
| CVE-2026-7557 | Critical (9.1) | 0.46% | — | Aug 5, 2026 | An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass… |
| CVE-2026-7329 | Critical (9.9) | 0.57% | — | Aug 5, 2026 | An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to… |
| CVE-2026-7327 | High (8.1) | 0.39% | — | Aug 5, 2026 | An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate… |
| CVE-2026-7326 | High (8.8) | 0.21% | — | Aug 5, 2026 | A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.