Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-7329: MarkLogic Server: Privilege Escalation via Low-Privileged User
CVE-2026-7329 · published 1 month ago
Summary
An authenticated user with limited access to MarkLogic Server can gain full administrator privileges, allowing them to access and modify sensitive data. This vulnerability affects versions before 11.3.6 and 12.0.3. To protect your system, update to the latest version or apply the recommended security patches.
What to do
- Update progress software corporation marklogic server to version 11.3.6 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| progress software corporation | marklogic server | < 11.3.6 |
Original advisory text
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-priv...
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.
Severity
9.9
Critical
CVSS 3.1: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published5 Aug 2026
Updated3 Sep 2026
First seen5 Aug 2026
Monitor software like this
Free during beta