Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Restrict network access to MarkLogic ODBC App Servers to trusted client networks. Disable ODBC App Servers that are not in active use, and do not expose ODBC ports to untrusted or internet-facing networks.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 05 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators. | |
| Title | Authentication bypass in Progress MarkLogic Server ODBC App Server | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-08-05T15:35:53.560Z
Reserved: 2026-05-21T15:17:40.656Z
Link: CVE-2026-9192
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T17:45:16Z
-
CWE-287
Improper Authentication