Cross-site request forgery in Progress MarkLogic Server Admin UI
Published Aug 5, 2026
8.8
HIGHCVSS 3.1
EPSS 0.21%
Description
A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration.
Affected products
-
- Version 11.0.0StatusaffectedConstraints<11.3.6
- Version 12.0.0StatusaffectedConstraints<12.0.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Progress Software Corporation | MarkLogic Server | unaffected |
|
- < 11.3.6
- ≥ 12.0.0 · < 12.0.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Restrict network access to the Admin UI to trusted internal networks. Use a reverse proxy to reject cross-origin requests to administrative endpoints. Administrators should avoid opening untrusted links while authenticated to the Admin UI and use a separate browser profile for administrative work.
References (2)
- https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026 vendor-advisoryVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53421 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026 | vendor-advisoryVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53421 | Advisory |
Change history (0)
No recorded changes yet.