TL;DR
Progress released an August 2026 bulletin for MarkLogic Server. It fixes ten MarkLogic Server vulnerabilities, several rated critical. The worst carry a CVSS score of 9.9. Progress urges all customers to upgrade as soon as possible.
- Total: 10 CVEs
- Severity: 7 Critical · 3 High
- Actively exploited: None confirmed
- Highest severity: 9.9 (Critical · CVSSv3) — CVE-2026-7329
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-7329 | 9.9 | CWE-269 | 11.3.6, 12.0.3 | Not exploited |
| CVE-2026-8709 | 9.9 | CWE-269 | 11.3.6, 12.0.3 | Not exploited |
| CVE-2026-9193 | 9.9 | CWE-269 | 11.3.6, 12.0.3 | Not exploited |
| CVE-2026-9192 | 9.8 | CWE-287 | 11.3.6, 12.0.3 | Not exploited |
| CVE-2026-9195 | 9.3 | CWE-22 | 11.3.6, 12.0.3 | Not exploited |
| CVE-2026-7557 | 9.1 | CWE-347 | 11.3.6, 12.0.3 | Not exploited |
| CVE-2026-9190 | 9.1 | CWE-444 | 11.3.6, 12.0.3 | Not exploited |
| CVE-2026-9203 | 8.5 | CWE-918 | 11.3.6, 12.0.3 | Not exploited |
Why it matters
MarkLogic stores enterprise data across many organizations. These MarkLogic Server vulnerabilities span privilege escalation, authentication bypass, and more. Together they could give an attacker full control of an affected instance.
How the attacks work
The bulletin covers several distinct weaknesses. Each targets a different part of the server.
Authentication bypass
CVE-2026-9192 lets an unauthenticated attacker skip password checks on the ODBC App Server. It scores 9.8. CVE-2026-7557 abuses weak SAML signature checks to impersonate any user. It scores 9.1.
Privilege escalation
Three flaws let low-privileged users reach administrator rights. CVE-2026-7329, CVE-2026-8709, and CVE-2026-9193 all score 9.9. Each exploits a different REST or Hadoop path.
Web and request-handling flaws
Other issues include HTTP request smuggling, cross-site scripting, CSRF, and SSRF. The SSRF flaw can expose cloud credentials from instance metadata.
Exploitation status
Progress has not reported any in-the-wild exploitation. No public proof-of-concept has been confirmed for these flaws.
Affected versions
The bulletin affects MarkLogic Server 12.0.0 through 12.0.1 and 11.0.0 through 11.3.4. Version 10.x and earlier are also affected.
Patch and mitigation
Upgrade now. Progress fixed the flaws in MarkLogic Server 12.0.3 and 11.3.6. Retired releases should move to a supported, fixed build. Full details appear in the MarkLogic Critical Security Alert Bulletin for August 2026.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.