CVE-2026-7557 – Progress MarkLogic Server
“Multiple critical flaws can turn limited or unauthenticated access into administrator-level control and sensitive data exposure.”
Progress MarkLogic Server before 11.3.6 and 12.0.3 is affected by ten High and Critical vulnerabilities. CVE-2026-7329, CVE-2026-8709, and CVE-2026-9193 each have a CVSS score of 9.9, Critical severity. CVE-2026-9192 has a CVSS score of 9.8, Critical severity. CVE-2026-9195 has a CVSS score of 9.3, Critical severity. CVE-2026-7557 and CVE-2026-9190 each have a CVSS score of 9.1, Critical severity. CVE-2026-9203, CVE-2026-7327, and CVE-2026-7326 have CVSS scores of 8.5, 8.1, and 7.5 respectively, all High severity.
The vulnerabilities include privilege escalation to administrator, SAML and ODBC authentication bypass, HTTP request smuggling, SSRF, cross-site scripting, and CSRF. MarkLogic Server 11.3.6 and 12.0.3 address these weaknesses.
CVE List:
CVE-2026-7329 (9.9)
CVE-2026-7557 (9.1)
CVE-2026-8709 (9.9)
CVE-2026-9190 (9.1)
CVE-2026-9192 (9.8)
CVE-2026-9193 (9.9)
CVE-2026-9195 (9.3)
CVE-2026-7327 (8.1)
CVE-2026-9203 (8.5)
CVE-2026-7326 (7.5)
Key Details
- Affected Product
- Progress Marklogic Server
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-347