Cross-Site Request Forgery in Progress MarkLogic Server
CVE-2026-7326

7.5HIGH

Key Information:

Vendor
CVE Published:
5 August 2026

What is CVE-2026-7326?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Admin UI of Progress MarkLogic Server prior to versions 11.3.6 and 12.0.3. This vulnerability permits a remote attacker to lure authenticated administrators to malicious web pages, enabling the execution of administrative actions on their behalf. Such unauthorized actions can lead to critical changes in security configurations, putting the integrity of the system at risk.

Affected Version(s)

MarkLogic Server 11.0.0 < 11.3.6

MarkLogic Server 12.0.0 < 12.0.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Birendrasah4u2 via Bugcrowd
.