SB2026080639 - Multiple vulnerabilities in Progress MarkLogic Server



SB2026080639 - Multiple vulnerabilities in Progress MarkLogic Server

Published: August 6, 2026

Security Bulletin ID SB2026080639
CSH Severity
High
Patch available
YES
Number of vulnerabilities 10
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 30% Medium 50% Low 20%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 10 vulnerabilities.


1) Cross-site request forgery (CVE-ID: CVE-2026-7326)

CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform administrative actions on behalf of an authenticated administrator.

The vulnerability exists due to cross-site request forgery in administrative functions when an authenticated administrator visits a malicious page. A remote attacker can lure an authenticated administrator to a malicious page to perform administrative actions on behalf of an authenticated administrator.

This may result in unauthorized changes to security configuration.


2) Improper privilege management (CVE-ID: CVE-2026-7327)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive server-side data.

The vulnerability exists due to improper privilege management in the REST API document processing pipeline when processing documents through the REST API. A remote user can exploit the flaw to disclose sensitive server-side data.

Exploitation requires access by a higher-privileged user to the affected content.


3) Improper privilege management (CVE-ID: CVE-2026-7329)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges to administrator.

The vulnerability exists due to improper privilege management in a REST query endpoint when handling REST queries. A remote user can exploit the affected endpoint to escalate privileges to administrator.

This enables execution of privileged operations and unauthorized data access.


4) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2026-7557)

CWE-ID: CWE-347 - Improper Verification of Cryptographic Signature

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication and impersonate any user.

The vulnerability exists due to improper verification of cryptographic signature in the SAML authentication module when processing a SAML response. A remote attacker can submit a crafted SAML response to bypass authentication and impersonate any user.

Administrator accounts can also be impersonated.


5) Improper privilege management (CVE-ID: CVE-2026-8709)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper privilege management in the REST document patch operation when processing document patch requests. A remote user can exploit the patch operation to escalate privileges.

This enables execution of privileged operations against the Security database.


6) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-9190)

CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials.

The vulnerability exists due to inconsistent interpretation of HTTP requests in the MarkLogic HTTP App Server when parsing HTTP requests. A remote attacker can send specially crafted HTTP requests to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials.


7) Improper Authentication (CVE-ID: CVE-2026-9192)

CWE-ID: CWE-287 - Improper Authentication

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute queries with the privileges of any named user known to the server.

The vulnerability exists due to improper authentication in the MarkLogic ODBC App Server when verifying passwords. A remote attacker can bypass password verification to execute queries with the privileges of any named user known to the server.

Administrator privileges can also be obtained by naming an administrator account known to the server.


8) Improper privilege management (CVE-ID: CVE-2026-9193)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper privilege management in the MarkLogic Hadoop integration when handling Hadoop integration operations. A remote user can exploit the integration flaw to escalate privileges.

This enables execution of privileged operations against the Security database.


9) Cross-site scripting (CVE-ID: CVE-2026-9195)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to execute arbitrary JavaScript in an authenticated administrator's browser session.

The vulnerability exists due to cross-site scripting in the MarkLogic Query Console when an authenticated administrator visits a crafted URL. A remote attacker can lure an authenticated administrator to a crafted URL to execute arbitrary JavaScript in an authenticated administrator's browser session.

This may allow credential capture and privileged actions to be performed on the administrator's behalf.


10) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-9203)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose cloud credentials.

The vulnerability exists due to server-side request forgery in protections against requests to cloud instance metadata endpoints when sending requests to cloud instance metadata endpoints. A remote user can bypass the protections to disclose cloud credentials.

This can enable onward compromise of cloud resources accessible to the host instance.


Remediation

Install update from vendor's website.