Cross-Site Request Forgery in Progress MarkLogic Server
CVE-2026-7326
7.5HIGH
What is CVE-2026-7326?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Admin UI of Progress MarkLogic Server prior to versions 11.3.6 and 12.0.3. This vulnerability permits a remote attacker to lure authenticated administrators to malicious web pages, enabling the execution of administrative actions on their behalf. Such unauthorized actions can lead to critical changes in security configurations, putting the integrity of the system at risk.
Affected Version(s)
MarkLogic Server 11.0.0 < 11.3.6
MarkLogic Server 12.0.0 < 12.0.3