Server-Side Request Forgery (SSRF) in MarkLogic - CVE-2026-9203
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to disclose cloud credentials.
The vulnerability exists due to server-side request forgery in protections against requests to cloud instance metadata endpoints when sending requests to cloud instance metadata endpoints. A remote user can bypass the protections to disclose cloud credentials.
This can enable onward compromise of cloud resources accessible to the host instance.