Cross-site request forgery in MarkLogic - CVE-2026-7326
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform administrative actions on behalf of an authenticated administrator.
The vulnerability exists due to cross-site request forgery in administrative functions when an authenticated administrator visits a malicious page. A remote attacker can lure an authenticated administrator to a malicious page to perform administrative actions on behalf of an authenticated administrator.
This may result in unauthorized changes to security configuration.