CVE-2026-7326

EUVD-2026-53421
A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 4.41%
Affected Products (NVD)
VendorProductVersion
progressmarklogic_server
𝑥
< 11.3.6
progressmarklogic_server
12.0.0 ≤
𝑥
< 12.0.3
𝑥
= Vulnerable software versions