Description
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.
Published: 2026-08-05
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper privilege management issue in the Hadoop integration of Progress MarkLogic Server allows an authenticated user with a low-privileged Hadoop role to elevate privileges and perform privileged operations against the server’s Security database. Because the flaw lies in access control (CWE-269), the role boundary is not enforced correctly and a malicious actor can change security settings, potentially exposing, deleting, or corrupting sensitive data. The vulnerability is not a remote code execution flaw; it relies on the existence of valid credentials and Hadoop role assignments.

Affected Systems

The affected product is Progress Software Corporation’s MarkLogic Server. Versions before 11.3.6 and before 12.0.3 contain the vulnerable Hadoop integration module. The flaw exists in the MLCP component and the XDBC App Server used for Hadoop integration. Only nodes with Hadoop integration enabled are impacted; if a deployment does not use Hadoop integration, the software is not exposed to this issue.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.9, indicating a very high severity. No EPSS score is available, and it is not yet listed in the CISA KEV catalog. Attackers can exploit it by authenticating with a low-privileged Hadoop role, then using the Hadoop integration interface to gain higher privileges and execute privileged operations against the Security database. The attack requires no additional privileges beyond those granted by the low-privileged Hadoop role and no additional exploitation steps. Because the flaw directly impacts access control, the consequences include unauthorized data disclosure, modification, and potential compromise of system integrity.

Generated by OpenCVE AI on August 5, 2026 at 18:07 UTC.

Remediation

Vendor Workaround

Restrict Hadoop integration privileges to users who require MLCP or Hadoop integration. Restrict network access to XDBC App Servers used for MLCP operations to trusted hosts. Disable XDBC App Servers used for MLCP if they are not required.


OpenCVE Recommended Actions

  • Update MarkLogic Server to version 11.3.6, 12.0.3, or later to apply the vendor patch.
  • Restrict Hadoop integration privileges to users who require MLCP or Hadoop integration.
  • Limit network access to XDBC App Servers used for MLCP operations to trusted hosts only.
  • If XDBC App Servers are not required, disable them to eliminate the attack surface.

Generated by OpenCVE AI on August 5, 2026 at 18:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.
Title Privilege escalation in Progress MarkLogic Server Hadoop integration
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-08-05T18:41:51.324Z

Reserved: 2026-05-21T15:19:27.735Z

Link: CVE-2026-9193

cve-icon Vulnrichment

Updated: 2026-08-05T18:11:06.626Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T18:15:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management