CVE-2026-9195: Cross-site scripting in Progress MarkLogic Server Query Console
A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions on the administrator's behalf.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9195?
The severity of CVE-2026-9195 is critical with a score of 9.3.
How do I fix CVE-2026-9195?
To fix CVE-2026-9195, upgrade Progress MarkLogic Server to version 11.3.6 or later, or version 12.0.3 or later.
What type of vulnerability is CVE-2026-9195?
CVE-2026-9195 is categorized as a cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-9195?
CVE-2026-9195 affects authenticated administrators using the Query Console of Progress MarkLogic Server.
What can an attacker do with CVE-2026-9195?
An attacker can execute arbitrary JavaScript in an administrator's browser session, potentially capturing credentials.