Server-Side Request Forgery in Progress MarkLogic Server Affects Cloud Security
CVE-2026-9203
8.5HIGH
What is CVE-2026-9203?
A server-side request forgery vulnerability exists in Progress MarkLogic Server prior to versions 11.3.6 and 12.0.3. This flaw allows an authenticated user with limited privileges to bypass security measures intended to protect cloud instance metadata endpoints. If exploited, this vulnerability can lead to the unauthorized disclosure of cloud credentials, potentially compromising cloud resources linked to the affected host instance.
Affected Version(s)
MarkLogic Server AWS 11.0.0 < 11.3.6
MarkLogic Server AWS 12.0.0 < 12.0.3