CVE-2026-7557 – Progress MarkLogic Server

CVSS 9.1 CRITICAL Critical - Same Day Deployment

“Multiple critical flaws can turn limited or unauthenticated access into administrator-level control and sensitive data exposure.”

Progress MarkLogic Server before 11.3.6 and 12.0.3 is affected by ten High and Critical vulnerabilities. CVE-2026-7329, CVE-2026-8709, and CVE-2026-9193 each have a CVSS score of 9.9, Critical severity. CVE-2026-9192 has a CVSS score of 9.8, Critical severity. CVE-2026-9195 has a CVSS score of 9.3, Critical severity. CVE-2026-7557 and CVE-2026-9190 each have a CVSS score of 9.1, Critical severity. CVE-2026-9203, CVE-2026-7327, and CVE-2026-7326 have CVSS scores of 8.5, 8.1, and 7.5 respectively, all High severity.

The vulnerabilities include privilege escalation to administrator, SAML and ODBC authentication bypass, HTTP request smuggling, SSRF, cross-site scripting, and CSRF. MarkLogic Server 11.3.6 and 12.0.3 address these weaknesses.

CVE List:
CVE-2026-7329 (9.9)
CVE-2026-7557 (9.1)
CVE-2026-8709 (9.9)
CVE-2026-9190 (9.1)
CVE-2026-9192 (9.8)
CVE-2026-9193 (9.9)
CVE-2026-9195 (9.3)
CVE-2026-7327 (8.1)
CVE-2026-9203 (8.5)
CVE-2026-7326 (7.5)

Key Details

Affected Product
Progress Marklogic Server
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-347
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.