All CVEs
Vulnerability intelligence

CVE-2026-9192

Progress Software Corporation MarkLogic Server CWE-287

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.

CVSS Score
9.8
Critical
EPSS — Exploit Probability
0.5%
Riskier than 43% of all CVEs · checked 2026-09-24
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Aug 11, 2026 · latest Aug 11, 2026

Coverage timeline

Related CVEs — Progress Software Corporation