Impact
A flaw in the REST API document patch operation in Progress MarkLogic Server allows an authenticated user with a low‑privileged REST role to elevate privileges and perform privileged operations against the Security database. The vulnerability, categorized as CWE‑269, lets the attacker gain elevated rights; however the CVE description does not explicitly state whether credential compromise or exploitation of additional vulnerabilities is required. The consequence is loss of system integrity and potential full administrative control over the server.
Affected Systems
The affected product is Progress Software Corporation’s MarkLogic Server. Versions prior to 11.3.6 and prior to 12.0.3 are vulnerable. No additional version details are provided.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical level of severity. EPSS is not available, so the current exploitation probability is unknown, but the lack of a KEV listing suggests no publicly known exploit yet. An attacker must be authenticated with a low‑privileged REST role and can invoke the vulnerable REST patch endpoint to elevate privileges. Once elevated, the attacker can execute arbitrary operations against the Security database.
OpenCVE Enrichment