CVE-2026-9192: An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password ver
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-9192
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-9192 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for An authentication bypass
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-9203: A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0…nvd · 2026-08-05
- criticalCVE-2026-9190: An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server bef…nvd · 2026-08-05
- mediumCVE-2026-49331: A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-…nvd · 2026-08-05
- criticalCisco Secure Firewall Management Center Software Authentication Bypass Vulnerabilitycisco-psirt · 2026-08-05
- criticalCVE-2026-70552: MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX disp…nvd · 2026-08-04
- highCVE-2026-18830: Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated…nvd · 2026-08-04
More from NVD Recent CVEs
- highCVE-2026-9203: A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0…2026-08-05
- criticalCVE-2026-9195: A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 1…2026-08-05
- criticalCVE-2026-9193: An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic …2026-08-05
- criticalCVE-2026-9190: An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server bef…2026-08-05
- criticalCVE-2026-8709: An improper privilege management vulnerability in the REST API document patch operation of Prog…2026-08-05