Back

HIGH

Cross-site request forgery in Progress MarkLogic Server Admin UI

Published Aug 5, 2026

Description

A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration.

Affected products

Remediation

Vendor solution

Restrict network access to the Admin UI to trusted internal networks. Use a reverse proxy to reject cross-origin requests to administrative endpoints. Administrators should avoid opening untrusted links while authenticated to the Admin UI and use a separate browser profile for administrative work.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ProgressSoftware
Published Aug 5, 2026
Updated Aug 7, 2026
Reserved Apr 28, 2026
CISA Vulnrichment
Updated Aug 5, 2026
NVD
Status Analyzed
Modified Sep 3, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ProgressSoftware
Published Aug 5, 2026
Updated Aug 7, 2026
Exploited since n/a
EUVD-2026-53421