Description
An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.
Published: 2026-08-05
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the REST API document patch operation in Progress MarkLogic Server allows an authenticated user with a low‑privileged REST role to elevate privileges and perform privileged operations against the Security database. The vulnerability, categorized as CWE‑269, lets the attacker gain elevated rights; however the CVE description does not explicitly state whether credential compromise or exploitation of additional vulnerabilities is required. The consequence is loss of system integrity and potential full administrative control over the server.

Affected Systems

The affected product is Progress Software Corporation’s MarkLogic Server. Versions prior to 11.3.6 and prior to 12.0.3 are vulnerable. No additional version details are provided.

Risk and Exploitability

The CVSS score of 9.9 indicates a critical level of severity. EPSS is not available, so the current exploitation probability is unknown, but the lack of a KEV listing suggests no publicly known exploit yet. An attacker must be authenticated with a low‑privileged REST role and can invoke the vulnerable REST patch endpoint to elevate privileges. Once elevated, the attacker can execute arbitrary operations against the Security database.

Generated by OpenCVE AI on August 5, 2026 at 18:07 UTC.

Remediation

Vendor Workaround

Restrict REST API write privileges to accounts that require them. Review REST API service accounts and remove write access from accounts that do not require it.


OpenCVE Recommended Actions

  • Upgrade to MarkLogic Server 11.3.6 or 12.0.3 or later if a patch is available.
  • Restrict REST API write privileges to only those accounts that require them.
  • Review and delete write access from any REST service accounts that do not need it.
  • Monitor for anomalous privilege escalation attempts and audit REST API usage.

Generated by OpenCVE AI on August 5, 2026 at 18:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.
Title Privilege escalation in Progress MarkLogic Server REST document patch operation
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-08-05T18:42:17.061Z

Reserved: 2026-05-15T19:43:47.533Z

Link: CVE-2026-8709

cve-icon Vulnrichment

Updated: 2026-08-05T18:11:09.151Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T18:15:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management