← All CVEs

CVE-2026-9192

critical · 9.8

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.

9.8
CVSS
0.5%
EPSS (exploit prob.)
43rd
EPSS percentile
2026-08-05
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-287

Affected products

VendorProductAffected versions
progressmarklogic_server< 11.3.6
progressmarklogic_server>= 12.0.0, < 12.0.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-9192