CVE-2026-9192 PUBLISHED

Authentication bypass in Progress MarkLogic Server ODBC App Server

Assigner: ProgressSoftware
Reserved: 21.05.2026 Published: 05.08.2026 Updated: 05.08.2026

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Progress Software Corporation
Product MarkLogic Server
Versions Default: unaffected
  • affected from 11.0.0 to 11.3.6 (excl.)
  • affected from 12.0.0 to 12.0.3 (excl.)

Workarounds

Restrict network access to MarkLogic ODBC App Servers to trusted client networks. Disable ODBC App Servers that are not in active use, and do not expose ODBC ports to untrusted or internet-facing networks.

References

Problem Types

  • CWE-287: Improper Authentication CWE

Impacts

  • Authentication Bypass