Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-7329: MarkLogic Server: Privilege Escalation via Low-Privileged User

CVE-2026-7329 · published 1 month ago
Summary

An authenticated user with limited access to MarkLogic Server can gain full administrator privileges, allowing them to access and modify sensitive data. This vulnerability affects versions before 11.3.6 and 12.0.3. To protect your system, update to the latest version or apply the recommended security patches.

What to do
  • Update progress software corporation marklogic server to version 11.3.6 or later.
Affected software
VendorProductAffected versions
progress software corporation marklogic server < 11.3.6
Original advisory text
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-priv...
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.
Severity
9.9 Critical
CVSS 3.1: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published5 Aug 2026
Updated3 Sep 2026
First seen5 Aug 2026
Sources
CVE-2026-7329 · NVD
CVE-2026-7329 · MITRE
Monitor software like this
Free during beta