Cross-site scripting in MarkLogic - CVE-2026-9195
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in an authenticated administrator's browser session.
The vulnerability exists due to cross-site scripting in the MarkLogic Query Console when an authenticated administrator visits a crafted URL. A remote attacker can lure an authenticated administrator to a crafted URL to execute arbitrary JavaScript in an authenticated administrator's browser session.
This may allow credential capture and privileged actions to be performed on the administrator's behalf.