CVE-2026-9192General(progress / marklogic_server)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch progress marklogic_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • marklogic_server

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
marklogic_server

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-05: 2Patch / Workaround · 2026-08-05: 1Technical Details · 2026-08-05: 208-05
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-9192 Authentication Bypass in Progress MarkLogic Server ODBC App Server Before 11.3.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9192

    Post summary

    A brief notice identifies CVE-2026-9192, an authentication bypass in MarkLogic Server ODBC App Server prior to 11.3.6, with a link to Vulmon for more details but no further exploitation or mitigation information.

    0000083
    4.1K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Progress MarkLogic ODBC App Server Auth Bypass (CVE-2026-9192) Progress MarkLogic Server ODBC App Server contains an auth bypass that lets unauthenticated remote attackers bypass password verification and submit queries as any known username (incl. admin), resulting in full data access and potential system takeover. 👉Affected: Progress MarkLogic Server < 11.3.6, 12.0.0-12.0.2 | Upgrade to 11.3.6 / 12.0.3

    Post summary

    A new auth bypass vulnerability (CVE‑2026‑9192) permits unauthenticated remote attackers to assume any user’s identity and gain full data access on Progress MarkLogic Server versions before 11.3.6 and 12.0.3, and users are advised to upgrade to the patched releases.

    0000081
    282 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprogressmarklogic_server---

Explore more