Executive brief
Progress MarkLogic Server is a database platform commonly deployed in enterprise environments. A server-side request forgery vulnerability allows authenticated users with low-level access to bypass protections and access cloud metadata endpoints, potentially exposing cloud credentials and compromising cloud infrastructure and data accessible to the affected server.
Technical details
This server-side request forgery (SSRF) vulnerability in Progress MarkLogic Server before versions 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to circumvent protections designed to block access to cloud instance metadata endpoints. By crafting malicious requests, an attacker can reach sensitive cloud metadata services (such as AWS IMDSv1/v2, Azure IMDS, or GCP metadata services) that would normally be restricted. Successful exploitation discloses cloud credentials and API tokens, enabling further compromise of cloud resources and services tied to the host instance. The vulnerability requires valid authentication but does not require administrative privileges. Patches are available in versions 11.3.6 and 12.0.3 or later.
Affected products
- Progress MarkLogic Server before 11.3.6 and 12.0.3
Timeline
- 2026-08-05: disclosed