Full Report
Progress security advisory (AV26-781)
Analysis Summary
# Vulnerability: Multiple Critical Vulnerabilities in Progress MarkLogic Server
## CVE Details
- **CVE IDs:**
- CVE-2026-7326
- CVE-2026-7327
- CVE-2026-7329
- CVE-2026-7557
- CVE-2026-8709
- CVE-2026-9190
- CVE-2026-9192
- CVE-2026-9193
- CVE-2026-9195
- CVE-2026-9203
- **CVSS Score:** Not explicitly listed in the advisory, but categorized as "Critical" by the vendor.
- **CWE:** Not specified in the summary advisory.
## Affected Systems
- **Products:** Progress MarkLogic Server
- **Versions:**
- Versions prior to 11.3.6
- Versions prior to 12.0.3
- **Configurations:** Default installations of the affected versions.
## Vulnerability Description
While the advisory does not provide granular technical breakdowns for each individual CVE, the bundle is characterized as a "Critical Security Alert." These vulnerabilities typically involve flaws in the server's processing engine that could allow for unauthorized access, data manipulation, or service disruption within the MarkLogic environment.
## Exploitation
- **Status:** Not explicitly stated as exploited in the wild; however, the "Critical" designation suggests high risk.
- **Complexity:** Not specified (typically Low for critical web-based vulnerabilities).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Potential unauthorized access to sensitive database content).
- **Integrity:** High (Potential unauthorized modification of data).
- **Availability:** High (Potential denial of service or system compromise).
## Remediation
### Patches
Progress Software Corporation recommends upgrading to the following versions to resolve these issues:
- **MarkLogic Server 11.3.6** or later.
- **MarkLogic Server 12.0.3** or later.
### Workarounds
No specific functional workarounds were provided in the advisory. Immediate patching is the recommended course of action.
## Detection
- **Indicators of Compromise:** Monitor system logs for unusual administrative activity or unexpected spikes in database queries from unauthorized IP addresses.
- **Detection methods and tools:** Audit internal versioning of MarkLogic deployments against the affected version list.
## References
- **Vendor advisory:** hxxps[://]community[.]progress[.]com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026
- **Progress Trust Center:** hxxps[://]www[.]progress[.]com/trust-center
- **Cyber Centre Alert:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/progress-security-advisory-av26-781