CVE-2026-7329
Progress Software · MarkLogic Server
Progress MarkLogic Server contains an improper privilege management vulnerability in its query interfaces allowing authenticated users with low-privileged roles to escalate to administrator.
Executive summary
A critical privilege escalation vulnerability in Progress MarkLogic Server allows low-privileged authenticated users to gain administrative control over the system.
Vulnerability
This is an improper privilege management flaw (CWE-269) within the SQL, SPARQL, and Optic REST query interfaces. An attacker who has already authenticated as a low-privileged REST user can exploit this to perform unauthorized administrative actions and access sensitive data.
Business impact
Successful exploitation allows an attacker to bypass security controls and gain full administrative access to the database server. Given the CVSS score of 9.9, this represents a critical risk of total system compromise, unauthorized data exfiltration, and potential disruption of business-critical operations.
Remediation
Immediate Action: Upgrade to MarkLogic Server version 11.3.6, 12.0.3, or later as specified in the vendor security advisory.
Proactive Monitoring: Audit database access logs for unusual administrative activities or queries originating from accounts that typically do not perform such operations.
Compensating Controls: Restrict access to the REST query interfaces to authorized IP addresses via network-level controls or a Web Application Firewall to mitigate unauthorized access attempts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a severe risk to data integrity and system confidentiality. Organizations utilizing Progress MarkLogic Server should prioritize patching to the identified secure versions immediately to eliminate the privilege escalation path.