Description
A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.
Published: 2026-08-05
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A server‑side request forgery flaw in Progress MarkLogic Server permits a logged‑in user with low‑privileged roles to transmute outbound requests to cloud instance metadata endpoints. By doing so an attacker can read the credentials stored on the host and use them to compromise resources that belong to the same cloud account. The vulnerability is a classic example of remote code‑execution‑level access to cloud secrets, and is identified as CWE‑918.

Affected Systems

MarkLogic Server from Progress Software Corporation is affected if the instance is running a version prior to 11.3.6 or 12.0.3. Only authenticated users with roles that do not normally include network‑access privileges can exploit the flaw.

Risk and Exploitability

The CVSS score of 8.5 classifies this flaw as high‑severity and indicates significant impact. EPSS is not available, and the vulnerability is not currently listed in a CISA KEV publication. The likely attack vector is an authenticated user with low‑privileged roles who can bypass cloud metadata protection. Once misused, the attacker may read cloud credentials and subsequently gain control over cloud resources that are accessible to the host machine.

Generated by OpenCVE AI on August 5, 2026 at 17:40 UTC.

Remediation

Vendor Workaround

Restrict outbound access from MarkLogic Server hosts to cloud instance metadata services, enforce IMDSv2 on applicable cloud instances, and minimize assignment of roles that permit network access.


OpenCVE Recommended Actions

  • Restrict outbound access from MarkLogic Server hosts to cloud instance metadata services
  • Enforce IMDSv2 on applicable cloud instances
  • Minimize assignment of roles that permit network access
  • Check for and install the latest MarkLogic Server updates (11.3.6 or later for 11.x, 12.0.3 or later for 12.x)

Generated by OpenCVE AI on August 5, 2026 at 17:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.
Title Server-side request forgery in Progress MarkLogic Server
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-08-05T15:40:19.062Z

Reserved: 2026-05-21T16:33:24.765Z

Link: CVE-2026-9203

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T17:45:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)