Back

CRITICAL

Authentication bypass in Progress MarkLogic Server ODBC App Server

Published Aug 5, 2026

Description

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.

Affected products

Remediation

Vendor solution

Restrict network access to MarkLogic ODBC App Servers to trusted client networks. Disable ODBC App Servers that are not in active use, and do not expose ODBC ports to untrusted or internet-facing networks.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ProgressSoftware
Published Aug 5, 2026
Updated Aug 7, 2026
Reserved May 21, 2026
CISA Vulnrichment
Updated Aug 5, 2026
NVD
Status Analyzed
Modified Sep 3, 2026
Red Hat
Severity n/a
Public date n/a