Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-9192: MarkLogic Server ODBC App Server Allows Unauthenticated Access

CVE-2026-9192 · published 1 month ago
Summary

An older version of MarkLogic Server's ODBC App Server can be exploited by an attacker to access the server without a password. This means an attacker can run queries with the same permissions as a server administrator, potentially leading to unauthorized access to sensitive data. MarkLogic Server users should update to version 11.3.6 or 12.0.3 to fix this issue.

What to do
  • Update progress software corporation marklogic server to version 11.3.6 or later.
Affected software
VendorProductAffected versions
progress software corporation marklogic server < 11.3.6
Original advisory text
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and exe...
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published5 Aug 2026
Updated3 Sep 2026
First seen5 Aug 2026
Sources
CVE-2026-9192 · NVD
CVE-2026-9192 · MITRE
Monitor software like this
Free during beta