A critical cross-site scripting vulnerability exists in Progress MarkLogic Server's Query Console, affecting versions before 11.3.6 and 12.0.3. An attacker can exploit this by crafting a URL that, when visited by an authenticated administrator, executes arbitrary JavaScript in the administrator's browser session. This allows the attacker to capture credentials and perform actions as the administrator.
CRITICALProgress Software CorporationCVE published 2026-08-05
CVE-2026-9193 is an improper privilege management vulnerability in Progress MarkLogic Server's Hadoop integration. An authenticated user with a low-privileged Hadoop role can escalate privileges and execute privileged operations against the Security database. This vulnerability has a CVSS score of 9.9, indicating critical severity. The CVE record was published on 2026-08-05T16:17:10.183Z and has not been [truncated]
CRITICALProgress Software CorporationCVE published 2026-08-05
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T16:17:10.063Z and has not been modified since then. The authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named u [truncated]
CRITICALProgress Software CorporationCVE published 2026-08-05
An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Serv [truncated]
CRITICALProgress Software CorporationCVE published 2026-08-05
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled. The CVE record was published on 2026-08-05T16:17:09.437Z and h [truncated]
HIGHProgress Software CorporationCVE published 2026-08-05
The CVE-2026-7327 record describes an improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before versions 11.3.6 and 12.0.3. An authenticated user with an administrative REST role can exploit this vulnerability to escalate privileges, potentially allowing unauthorized access to sensitive server-side data. Administrators and users of Progres [truncated]