Junglewise Threat Intelligence

CVE-2026-9195: Progress MarkLogic Server cross-site scripting in Query Console

CVE-2026-9195 · Severity: critical · CVSS 9.3 · Published 2026-08-05

Technologies: Progress Marklogic Server. Vendors: Progress.

Executive brief

MarkLogic Server is an enterprise database platform used to manage complex data. A cross-site scripting (XSS) vulnerability in the Query Console administrative interface allows an attacker to trick an authenticated administrator into visiting a malicious link, after which arbitrary JavaScript executes in the administrator's browser. This could lead to credential theft and unauthorized administrative actions, potentially compromising the entire database and customer data.

Technical details

A cross-site scripting (XSS) vulnerability exists in the Query Console component of Progress MarkLogic Server versions before 11.3.6 and 12.0.3. The vulnerability is triggered when a remote attacker crafts a malicious URL and lures an authenticated administrator to visit it. Upon navigation, unsanitized user input is reflected in the page and executed as JavaScript in the administrator's browser context. This allows the attacker to capture session credentials, perform administrative actions on the database, and potentially escalate privileges. No user interaction beyond clicking a link is required once the administrator is authenticated. Patches are available in MarkLogic Server 11.3.6 and 12.0.3 and later versions.

Affected products

  • Progress MarkLogic Server before 11.3.6, before 12.0.3

Timeline

  • 2026-08-05: disclosed

References

Related threats