Executive brief
Progress MarkLogic Server is an enterprise XML and JSON database platform with an administrative web interface. A cross-site request forgery (CSRF) vulnerability allows an attacker to trick an authenticated administrator into visiting a malicious webpage, which can then silently perform unauthorized administrative actions such as modifying security configuration without the administrator's knowledge or consent.
Technical details
A cross-site request forgery vulnerability exists in the Admin UI of Progress MarkLogic Server. The vulnerability allows a remote attacker to perform unauthorized administrative actions on behalf of an authenticated administrator by luring them to a malicious web page. The attack requires that an administrator be logged into MarkLogic and then visit the attacker-controlled page, leveraging the administrator's existing session to make unwanted configuration changes, including security-related modifications. The vulnerability affects MarkLogic Server versions before 11.3.6 and 12.0.3. Patches are available in the mentioned versions.
Affected products
- Progress MarkLogic Server before 11.3.6 and 12.0.3
Timeline
- 2026-08-05: disclosed