Vulnerability intelligence
CVE-2026-9192
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.
CVSS Score
9.8
Critical
EPSS — Exploit Probability
0.5%
Riskier than 43% of all CVEs · checked 2026-09-24
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Aug 11, 2026 · latest Aug 11, 2026
Coverage timeline
-
MarkLogic Server Security Bulletin Patches 10 Vulnerabilities, With CVSS Scores Up to 9.9securityonline.info · Aug 11, 2026