CVE-2026-9192

Summary

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.

Affected Software

VendorProductVersion RangeStatus
Progress Software CorporationMarkLogic Server11.0.0 < 11.3.6affected
Progress Software CorporationMarkLogic Server12.0.0 < 12.0.3affected

Weaknesses

  • CWE-287: CWE-287: Improper Authentication

Workarounds

Restrict network access to MarkLogic ODBC App Servers to trusted client networks. Disable ODBC App Servers that are not in active use, and do not expose ODBC ports to untrusted or internet-facing networks.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References