Junglewise Threat Intelligence

CVE-2026-7326: Progress MarkLogic Server cross-site request forgery in Admin UI

CVE-2026-7326 · Severity: high · CVSS 7.5 · Published 2026-08-05

Technologies: Progress Marklogic Server. Vendors: Progress.

Executive brief

Progress MarkLogic Server is an enterprise XML and JSON database platform with an administrative web interface. A cross-site request forgery (CSRF) vulnerability allows an attacker to trick an authenticated administrator into visiting a malicious webpage, which can then silently perform unauthorized administrative actions such as modifying security configuration without the administrator's knowledge or consent.

Technical details

A cross-site request forgery vulnerability exists in the Admin UI of Progress MarkLogic Server. The vulnerability allows a remote attacker to perform unauthorized administrative actions on behalf of an authenticated administrator by luring them to a malicious web page. The attack requires that an administrator be logged into MarkLogic and then visit the attacker-controlled page, leveraging the administrator's existing session to make unwanted configuration changes, including security-related modifications. The vulnerability affects MarkLogic Server versions before 11.3.6 and 12.0.3. Patches are available in the mentioned versions.

Affected products

  • Progress MarkLogic Server before 11.3.6 and 12.0.3

Timeline

  • 2026-08-05: disclosed

References

Related threats