Improper Authentication in MarkLogic - CVE-2026-9192

 

Improper Authentication in MarkLogic - CVE-2026-9192

Published: August 6, 2026


Vulnerability identifier: #VU141064
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-9192
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute queries with the privileges of any named user known to the server.

The vulnerability exists due to improper authentication in the MarkLogic ODBC App Server when verifying passwords. A remote attacker can bypass password verification to execute queries with the privileges of any named user known to the server.

Administrator privileges can also be obtained by naming an administrator account known to the server.


Affected software

MarkLogic

How to mitigate CVE-2026-9192

Install security update from vendor's website.

MarkLogic - addressed in versions 11.3.6, 12.0.3

External References

Related Security Bulletins