CVE-2026-7326: Cross-site request forgery in Progress MarkLogic Server Admin UI
A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress MarkLogic Serverto a version that resolves this vulnerability.Fixed in 11.3.6 - Upgrade
Upgrade
Progress MarkLogic Serverto a version that resolves this vulnerability.Fixed in 12.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7326?
CVE-2026-7326 has a severity rating of high (7.5).
How do I fix CVE-2026-7326?
To mitigate CVE-2026-7326, upgrade the Progress MarkLogic Server to version 11.3.6 or 12.0.3 or later.
What type of attack does CVE-2026-7326 involve?
CVE-2026-7326 involves a cross-site request forgery (CSRF) attack.
Who is affected by CVE-2026-7326?
CVE-2026-7326 affects authenticated administrators using the Admin UI of Progress MarkLogic Server.
What impact can CVE-2026-7326 have?
CVE-2026-7326 can allow attackers to perform unauthorized administrative actions on behalf of the administrator.