AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-7326

HIGH · CVSS 7.5 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server prior to versions 11.3.6 and 12.0.3 allows remote attackers to exploit authenticated administrators by tricking them into visiting malicious web pages. This could lead to unauthorized modifications of security configurations, potentially compromising the integrity of the system. Organizations using affected versions should prioritize patching to mitigate the risk of administrative actions being performed without consent.

CVE
CVE-2026-7326
Severity
HIGH
CVSS
7.5
EPSS
0.14%

Original NVD Description

A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration.