Server-side request forgery in Progress MarkLogic Server
Published Aug 5, 2026
8.5
HIGHCVSS 3.1
EPSS 0.34%
Description
A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.
Affected products
-
Affected
- ≥ 11.0.0, < 11.3.6
- ≥ 12.0.0, < 12.0.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Progress Software Corporation | MarkLogic Server | unaffected | Affected
|
- < 11.3.6
- ≥ 12.0.0 · < 12.0.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Restrict outbound access from MarkLogic Server hosts to cloud instance metadata services, enforce IMDSv2 on applicable cloud instances, and minimize assignment of roles that permit network access.
References (2)
- https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026 vendor-advisoryVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53431 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026 | vendor-advisoryVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53431 | Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data