Security Advisory

CVE-2026-9203

8.5
HIGH

Vulnerability Description

A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.
Published Date August 5, 2026
Official Source NIST NVD Advisory