Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-8709: Progress MarkLogic Server: Low-Privilege User Escalation via Patch Operation
CVE-2026-8709 · published 1 month ago
Summary
A vulnerability in Progress MarkLogic Server's REST API document patch operation allows a low-privileged user to gain more access. This could allow an unauthorized user to make changes to sensitive data. Update to version 11.3.6 or 12.0.3 to fix the issue.
What to do
- Update progress software corporation marklogic server to version 11.3.6 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| progress software corporation | marklogic server | < 11.3.6 |
Original advisory text
An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST...
An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.
Severity
9.9
Critical
CVSS 3.1: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published5 Aug 2026
Updated30 Aug 2026
First seen5 Aug 2026
Monitor software like this
Free during beta