---
id: CVE-2026-9192
title: >-
  An authentication bypass vulnerability in the ODBC App Server of Progress
  MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote
  attacker to bypass password verification and execute queries with the
  privileges of any …
summary: >-
  An authentication bypass vulnerability in the ODBC App Server of Progress
  MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote
  attacker to bypass password verification and execute queries with the
  privileges of any …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-287
published: '2026-08-05'
updated: '2026-08-28'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9192'
references:
  - url: >-
      https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026
    label: security@progress.com
tags:
  - nvd
epss: 0.00524
epssPercentile: 0.43408
ingestedAt: '2026-08-29T16:39:14.079Z'
---

## Overview

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
