THREAT OPS › Threat News › [NVD] CVE-2026-9195 (CRITICAL 9.3) — A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture crede
[NVD] CVE-2026-9195 (CRITICAL 9.3) — A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture crede
CVE-2026-9195 CVSS: 9.3 CRITICAL Published: 2026-08-05T16:17:10.313
A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions on the admin
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-9195cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-9195