Back

HIGH

Server-side request forgery in Progress MarkLogic Server

Published Aug 5, 2026

Description

A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.

Affected products

Remediation

Vendor solution

Restrict outbound access from MarkLogic Server hosts to cloud instance metadata services, enforce IMDSv2 on applicable cloud instances, and minimize assignment of roles that permit network access.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner ProgressSoftware
Published Aug 5, 2026
Updated Aug 7, 2026
Reserved May 21, 2026

CISA Vulnrichment

Updated Aug 5, 2026

NVD

Status Analyzed
Modified Sep 3, 2026

Red Hat

No data

ENISA EUVD

Assigner ProgressSoftware
Published Aug 5, 2026
Updated Aug 7, 2026

GitHub

No data