CVE-2026-9192
Progress Software · MarkLogic Server
Progress MarkLogic Server contains an authentication bypass vulnerability in the ODBC App Server, allowing unauthenticated attackers to execute queries with administrative privileges.
Executive summary
An authentication bypass in Progress MarkLogic Server allows unauthenticated remote attackers to execute arbitrary queries with elevated privileges.
Vulnerability
The flaw resides in the ODBC App Server component and allows an unauthenticated remote attacker to bypass password verification. This permits the execution of database queries using the permissions of any known user, including administrative accounts.
Business impact
Successful exploitation allows an attacker to bypass security controls entirely, leading to unauthorized access to sensitive data, data manipulation, or administrative system takeovers. The CVSS score of 9.8 reflects the high risk of this vulnerability, which could result in severe data breaches and loss of system integrity.
Remediation
Immediate Action: Update MarkLogic Server to version 11.3.6, 12.0.3, or later as specified in the vendor security advisory.
Proactive Monitoring: Audit database logs for unauthorized query patterns or unexpected access by administrative accounts originating from external IP addresses.
Compensating Controls: Restrict network access to the ODBC App Server port to trusted internal IP addresses only, using host-based firewalls or network access control lists.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This is a critical vulnerability that requires immediate attention for all deployments of MarkLogic Server. Administrators should apply the provided vendor patches as soon as possible to prevent potential unauthorized database access and data exfiltration.