LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-9192

progress · marklogic server

Published
CVSS9.8
Severitycritical
WeaknessCWE-287
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-9192

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-9192.