CVE-2026-9203

Summary

A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.

Affected Software

VendorProductVersion RangeStatus
Progress Software CorporationMarkLogic Server11.0.0 < 11.3.6affected
Progress Software CorporationMarkLogic Server12.0.0 < 12.0.3affected

Weaknesses

  • CWE-918: CWE-918: Server-Side Request Forgery (SSRF)

Workarounds

Restrict outbound access from MarkLogic Server hosts to cloud instance metadata services, enforce IMDSv2 on applicable cloud instances, and minimize assignment of roles that permit network access.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References