


Perceptive Security
SOC/SIEM Consultancy

A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authentica…
Published:
4 August 2026 at 22:00:00
Alert date:
5 August 2026 at 17:04:40
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Database & Storage, Identity & Access
A reflected cross-site scripting (XSS) vulnerability has been identified in the Query Console component of Progress MarkLogic Server. The flaw affects versions prior to 11.3.6 and 12.0.3. A remote attacker can exploit this vulnerability by luring an authenticated administrator to visit a specially crafted URL. Upon successful exploitation, the attacker can execute arbitrary JavaScript within the administrator's browser session. This allows for credential capture and the ability to perform privileged administrative actions on behalf of the victim. The attack requires social engineering to trick the administrator into clicking a malicious link. Progress has issued a security bulletin classifying this as a critical security alert. Users are advised to upgrade to the patched versions 11.3.6 or 12.0.3 immediately.
Technical details
Mitigation steps:
Affected products:
Progress MarkLogic Server 11.x before 11.3.6
Progress MarkLogic Server 12.x before 12.0.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-9195
https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
