Description
A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration.
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A cross‑site request forgery (CSRF) flaw in the Administrative User Interface of Progress MarkLogic Server allows an attacker to coerce an authenticated administrator into executing privileged actions without the administrator's knowledge. By tricking the administrator into visiting a malicious web page, the attacker can cause the browser to send administrative requests that the server accepts, leading to unauthorized changes to security settings such as authentication policies, access controls, and configuration parameters. The flaw is identified as CWE‑352 and represents a high‑severity vulnerability because it enables configuration tampering that can compromise the integrity of the server.

Affected Systems

Vulnerabilities affect Progress MarkLogic Server versions prior to 11.3.6 in the 11.x release line and prior to 12.0.3 in the 12.x line. Any deployment that has not upgraded to at least these patched releases and exposes the Admin UI externally is subject to risk. The flaw exists in the admin portal delivered by the product and does not require additional components beyond the standard installation.

Risk and Exploitability

The CVSS score of 7.5 marks this flaw as high severity. Because the EPSS score is not available, the exact probability of exploitation remains unclear, but the lack of a KEV listing suggests no publicly known exploit code has been observed yet. However, the remote attack requires only an authenticated administrator to be lured to a malicious page, a scenario that is common in phishing campaigns. Consequently, organizations running unpatched MarkLogic Server instances should consider the risk high until a fix is applied.

Generated by OpenCVE AI on August 5, 2026 at 17:44 UTC.

Remediation

Vendor Workaround

Restrict network access to the Admin UI to trusted internal networks. Use a reverse proxy to reject cross-origin requests to administrative endpoints. Administrators should avoid opening untrusted links while authenticated to the Admin UI and use a separate browser profile for administrative work.


OpenCVE Recommended Actions

  • Restrict network access to the MarkLogic Admin UI to trusted internal networks using firewall rules or VPN so that only authorized users can reach the portal.
  • Configure a reverse proxy or web application firewall to reject cross‑origin requests targeting administrative endpoints and ensure the CSRF token check is enforced.
  • Educate administrators to open the Admin UI in a separate browser profile and avoid clicking untrusted links while logged in, and where possible enforce strict same‑origin policies.
  • Apply the vendor‑issued security patch for MarkLogic Server once it becomes available.

Generated by OpenCVE AI on August 5, 2026 at 17:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Progress Software Corporation
Progress Software Corporation marklogic Server
Vendors & Products Progress Software Corporation
Progress Software Corporation marklogic Server

Wed, 05 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration.
Title Cross-site request forgery in Progress MarkLogic Server Admin UI
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Progress Software Corporation Marklogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-08-07T03:55:23.079Z

Reserved: 2026-04-28T16:08:17.147Z

Link: CVE-2026-7326

cve-icon Vulnrichment

Updated: 2026-08-05T19:22:50.988Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-05T16:17:08.930

Modified: 2026-08-28T21:16:15.740

Link: CVE-2026-7326

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:06:12Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)