CVE-2026-9192: Authentication bypass in Progress MarkLogic Server ODBC App Server
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9192?
The severity of CVE-2026-9192 is critical with a CVSS score of 9.8.
How do I fix CVE-2026-9192?
To fix CVE-2026-9192, update Progress MarkLogic Server ODBC App Server to version 11.3.6 or later, or to version 12.0.3 or later.
What vulnerabilities are associated with CVE-2026-9192?
CVE-2026-9192 allows an unauthenticated remote attacker to execute queries by bypassing password verification.
Who is affected by CVE-2026-9192?
Any users of Progress MarkLogic Server ODBC App Server before versions 11.3.6 and 12.0.3 are affected by CVE-2026-9192.
What kind of attack can be executed using CVE-2026-9192?
An attacker can execute queries with the privileges of any named user, including administrators.