


Perceptive Security
SOC/SIEM Consultancy

An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authenti…
Published:
4 August 2026 at 22:00:00
Alert date:
5 August 2026 at 17:04:40
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Identity & Access, Database & Storage
CVE-2026-9190 describes a critical HTTP request smuggling vulnerability in the HTTP App Server component of Progress MarkLogic Server. Affected versions include all releases prior to 11.3.6 and 12.0.3. The vulnerability is triggered by crafted HTTP requests containing both Content-Length and Transfer-Encoding headers, causing desynchronization between a reverse proxy and MarkLogic Server in interpreting request boundaries. A remote unauthenticated attacker can exploit this to bypass authentication and authorization controls, hijack legitimate user sessions, or capture user credentials. The vulnerability poses a significant risk to organizations using MarkLogic as a backend data platform behind a reverse proxy. Progress has issued a critical security alert and patches are available in versions 11.3.6 and 12.0.3. Organizations are advised to upgrade immediately to mitigate exposure.
Technical details
Mitigation steps:
Affected products:
Progress MarkLogic Server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-9190
https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
