Description
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.
Published: 2026-08-05
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an unauthenticated remote attacker to bypass password verification in the ODBC App Server of Progress MarkLogic Server before version 11.3.6 and 12.0.3, enabling the attacker to execute queries with the credentials of any named user known to the server, including administrators. The flaw represents an authentication bypass (CWE‑287) that could lead to unauthorized data access, modification, and administrative control.

Affected Systems

Progress Software Corporation MarkLogic Server versions earlier than 11.3.6 and 12.0.3 are impacted, particularly wherever the ODBC App Server component is enabled. Any deployment using these versions should assess whether the ODBC interface is in use.

Risk and Exploitability

The CVSS score of 9.8 classifies this issue as critical. Although EPSS data is not available and the vulnerability is not listed in CISA KEV, the risk remains high because the flaw allows remote exploitation without authentication. An attacker can reach the vulnerable ODBC port from any network that has connectivity, making exploitation possible when the port is exposed to untrusted or internet‑facing networks.

Generated by OpenCVE AI on August 5, 2026 at 17:42 UTC.

Remediation

Vendor Workaround

Restrict network access to MarkLogic ODBC App Servers to trusted client networks. Disable ODBC App Servers that are not in active use, and do not expose ODBC ports to untrusted or internet-facing networks.


OpenCVE Recommended Actions

  • Upgrade MarkLogic Server to version 11.3.6 or 12.0.3, which contains the official fix.
  • Restrict network access to ODBC App Servers so that only trusted client networks can reach the ODBC ports.
  • Disable any ODBC App Servers that are not in active use and avoid exposing ODBC ports to untrusted networks.

Generated by OpenCVE AI on August 5, 2026 at 17:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.
Title Authentication bypass in Progress MarkLogic Server ODBC App Server
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-08-05T18:42:04.820Z

Reserved: 2026-05-21T15:17:40.656Z

Link: CVE-2026-9192

cve-icon Vulnrichment

Updated: 2026-08-05T18:14:42.426Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T17:45:16Z

Weaknesses