Improper Authentication in MarkLogic - CVE-2026-9192
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute queries with the privileges of any named user known to the server.
The vulnerability exists due to improper authentication in the MarkLogic ODBC App Server when verifying passwords. A remote attacker can bypass password verification to execute queries with the privileges of any named user known to the server.
Administrator privileges can also be obtained by naming an administrator account known to the server.