ZeroHour

CVE-2026-9203

CVSS 3.1
8.5 high
EPSS
<1%p12
Published
()
Modified
Description

A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.

Vendors
progress
Products
marklogic server
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.