Server-Side Request Forgery in Progress MarkLogic Server Affects Cloud Security
CVE-2026-9203

8.5HIGH

Key Information:

Vendor
CVE Published:
5 August 2026

What is CVE-2026-9203?

A server-side request forgery vulnerability exists in Progress MarkLogic Server prior to versions 11.3.6 and 12.0.3. This flaw allows an authenticated user with limited privileges to bypass security measures intended to protect cloud instance metadata endpoints. If exploited, this vulnerability can lead to the unauthorized disclosure of cloud credentials, potentially compromising cloud resources linked to the affected host instance.

Affected Version(s)

MarkLogic Server AWS 11.0.0 < 11.3.6

MarkLogic Server AWS 12.0.0 < 12.0.3

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

backslash via Bugcrowd
.