A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Restrict outbound access from MarkLogic Server hosts to cloud instance metadata services, enforce IMDSv2 on applicable cloud instances, and minimize assignment of roles that permit network access.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Progress Software Corporation
Progress Software Corporation marklogic Server
Vendors & Products Progress Software Corporation
Progress Software Corporation marklogic Server

Wed, 05 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.
Title Server-side request forgery in Progress MarkLogic Server
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-08-07T03:55:33.648Z

Reserved: 2026-05-21T16:33:24.765Z

Link: CVE-2026-9203

cve-icon Vulnrichment

Updated: 2026-08-05T18:10:59.955Z

cve-icon NVD

Status : Received

Published: 2026-08-05T16:17:10.437

Modified: 2026-08-07T05:17:04.810

Link: CVE-2026-9203

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:59Z

Weaknesses