CVE-2026-9192

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-05 16:17

Updated : 2026-09-03 14:49


NVD link : CVE-2026-9192

Mitre link : CVE-2026-9192

CVE.ORG link : CVE-2026-9192


JSON object : View

Products Affected

progress

  • marklogic_server
CWE
CWE-287

Improper Authentication