Progress MarkLogic Server是Progress公司的一款企业级数据库管理系统。 Progress MarkLogic Server 11.3.6之前版本和12.0.3之前版本存在跨站请求伪造漏洞,该漏洞源于Admin UI存在跨站请求伪造漏洞,可能导致远程攻击者引诱已认证管理员访问恶意网页,以管理员身份执行管理操作,导致未授权更改安全配置。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progress Software Corporation | MarkLogic Server | 11.0.0< 11.3.6 |
affected |
12.0.0< 12.0.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software Corporation | MarkLogic Server | 11.0.0 ~ 11.3.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7329 | 9.9 CRITICAL | Privilege escalation in Progress MarkLogic Server REST query interfaces |
| CVE-2026-9193 | 9.9 CRITICAL | Privilege escalation in Progress MarkLogic Server Hadoop integration |
| CVE-2026-8709 | 9.9 CRITICAL | Privilege escalation in Progress MarkLogic Server REST document patch operation |
| CVE-2026-9192 | 9.8 CRITICAL | Authentication bypass in Progress MarkLogic Server ODBC App Server |
| CVE-2026-9195 | 9.3 CRITICAL | Cross-site scripting in Progress MarkLogic Server Query Console |
| CVE-2026-7557 | 9.1 CRITICAL | SAML authentication bypass in Progress MarkLogic Server |
| CVE-2026-9190 | 9.1 CRITICAL | HTTP request smuggling in Progress MarkLogic Server |
| CVE-2026-9203 | 8.5 HIGH | Server-side request forgery in Progress MarkLogic Server |
| CVE-2026-7327 | 8.1 HIGH | Privilege escalation in Progress MarkLogic Server REST API document processing |
No comments yet