Description
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.
Published: 2026-08-05
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper privilege management flaw exists in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server, allowing a user with a low‑privileged REST role to elevate their privileges to administrator. This gives the attacker the ability to perform privileged operations and access sensitive data that should otherwise be restricted. The weakness corresponds to CWE‑269, which describes inconsistencies in authentication and authorization controls.

Affected Systems

The vulnerability affects Progress Software Corporation’s MarkLogic Server, specifically versions earlier than 11.3.6 for the 11.x line and preceding 12.0.3 for the 12.x line. Users of these releases should verify their installed version against these thresholds.

Risk and Exploitability

The CVSS score of 9.9 indicates a critical severity. No EPSS score is published, and the vulnerability is not currently listed in the CISA KEV catalog, which suggests it is not being actively exploited at large scale. The likely attack vector is through authenticated HTTP requests to the REST query endpoints; the description implies that an attacker must first compromise or create a user account with a low‑privileged REST role. Access to the interfaces over a trusted network or from a client with proper credentials would be sufficient to exploit the flaw, hence the CNA’s recommended workaround of restricting network access to the REST interfaces and minimizing REST role assignments.

Generated by OpenCVE AI on August 5, 2026 at 17:43 UTC.

Remediation

Vendor Workaround

Restrict network access to REST query interfaces to trusted users and networks. Minimize assignment of REST roles.


OpenCVE Recommended Actions

  • Apply the vendor’s latest patch or upgrade to MarkLogic Server 11.3.6 or newer, or 12.0.3 or newer, to address the privilege management flaw.
  • Restrict network access to the REST query interfaces so that only trusted users and networks can reach them.
  • Minimize the assignment of REST roles, ensuring that low‑privileged users receive only the permissions required for their tasks.

Generated by OpenCVE AI on August 5, 2026 at 17:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.
Title Privilege escalation in Progress MarkLogic Server REST query interfaces
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-08-05T18:42:28.404Z

Reserved: 2026-04-28T17:16:10.961Z

Link: CVE-2026-7329

cve-icon Vulnrichment

Updated: 2026-08-05T18:11:11.482Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T17:45:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management