CVE-2026-9203: Server-side request forgery in Progress MarkLogic Server
A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9203?
CVE-2026-9203 has a severity rating of 8.5, categorized as high.
How do I fix CVE-2026-9203?
To fix CVE-2026-9203, update Progress MarkLogic Server to version 11.3.6 or later, or to version 12.0.3 or later.
What impact does CVE-2026-9203 have on my system?
CVE-2026-9203 can allow an authenticated user with low privileges to bypass security and access cloud instance metadata, potentially leading to credential exposure.
What type of vulnerability is CVE-2026-9203?
CVE-2026-9203 is classified as a server-side request forgery (SSRF) vulnerability.
Who is affected by CVE-2026-9203?
CVE-2026-9203 affects users of Progress MarkLogic Server versions prior to 11.3.6 and 12.0.3.