🚨 CVE-2026-9190
An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Server to interpret request boundaries differently.
🎖@cveNotify
Progress
Marklogic Critical Security Alert Bulletin – August 2026 – (CVE-2026-7326, CVE-2026-7327, CVE-2026-7329, CVE-2026-7557, CVE-2026…
The Progress MarkLogic team confirmed several security vulnerabilities in MarkLogic Server, including privilege escalation, authentication bypass, cross-site request forgery, cross-site scripting, cross-origin resource sharing bypass, HTTP request smuggling…
September 3, 2026 42