Executive brief
Progress MarkLogic Server is a NoSQL document database used for storing and managing large volumes of structured and unstructured data. An unauthenticated attacker can bypass password verification on the ODBC App Server and execute database queries with administrator privileges, potentially leading to complete data compromise or destruction.
Technical details
This is an authentication bypass vulnerability in the ODBC (Open Database Connectivity) App Server component of MarkLogic Server. The vulnerability allows an unauthenticated remote attacker to bypass password verification mechanisms and execute arbitrary queries with the privileges of any named user, including system administrators. The attack is network-accessible and requires no prior authentication or user interaction. Affected versions include MarkLogic Server before 11.3.6 and before 12.0.3. Patches are available in versions 11.3.6 and 12.0.3 or later.
Affected products
- Progress MarkLogic Server before 11.3.6, before 12.0.3
Timeline
- 2026-08-05: disclosed