What is CVE-2026-7326?
CVE-2026-7326 is a Cross-Site Request Forgery (CSRF) vulnerability in the Admin UI of Progress MarkLogic Server versions before 11.3.6 and 12.0.3. A remote attacker can exploit this by tricking an authenticated administrator into visiting a malicious web page, leading to unauthorized administrative actions. Affected systems should be upgraded to MarkLogic Server version 11.3.6, 12.0.3, or later immediately.
Azərbaycanca: CVE-2026-7326, Progress MarkLogic Server-in 11.3.6 və 12.0.3-dən əvvəlki versiyalarında Admin UI-da aşkarlanmış Cross-Site Request Forgery (CSRF) zəifliyidir. Uzaqdan hücumçu, autentifikasiya olunmuş administratoru zərərli veb səhifəyə cəlb etməklə, onun adından icazəsiz inzibati əməliyyatlar həyata keçirə bilər. Təsirə məruz qalan serverlərdə dərhal MarkLogic Server-in 11.3.6, 12.0.3 və ya daha yuxarı versiyalarına yeniləmə aparılmalıdır.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
What action should be taken for systems affected by CVE-2026-7326?
Affected systems should be upgraded to MarkLogic Server version 11.3.6, 12.0.3, or later immediately.
How does an attacker target an authenticated administrator to exploit CVE-2026-7326?
The attacker can trick the authenticated administrator into visiting a malicious web page to perform unauthorized administrative actions on their behalf.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.