An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.
References
| Link | Resource |
|---|---|
| https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-05 16:17
Updated : 2026-09-03 14:49
NVD link : CVE-2026-9192
Mitre link : CVE-2026-9192
CVE.ORG link : CVE-2026-9192
JSON object : View
Products Affected
progress
- marklogic_server
CWE
CWE-287
Improper Authentication
