CVE-2026-9193

Progress Software · MarkLogic Server

Progress Software MarkLogic Server contains an improper privilege management flaw in its Hadoop integration, enabling authenticated users to escalate privileges and compromise the Security database.

Executive summary

A critical privilege escalation vulnerability in Progress Software MarkLogic Server allows low-privileged users to gain unauthorized administrative control over the Security database.

Vulnerability

This vulnerability involves improper privilege management within the Hadoop integration component. It allows an authenticated user with low-level Hadoop privileges to perform privileged operations against the Security database, effectively bypassing intended access controls.

Business impact

Successful exploitation grants an attacker administrative-level access to the Security database, which may contain sensitive credentials, user information, and system configuration data. Given the CVSS score of 9.9, this vulnerability presents a severe risk of total system compromise, potentially leading to unauthorized data exfiltration, permanent loss of data integrity, or complete denial of service.

Remediation

Immediate Action: Upgrade to MarkLogic Server version 11.3.6, 12.0.3, or later to address the underlying privilege management flaws.

Proactive Monitoring: Audit access logs for unusual administrative activity or unauthorized queries originating from low-privileged Hadoop service accounts.

Compensating Controls: Restrict network access to the Hadoop integration interface and enforce strict identity and access management policies for all users with Hadoop-related roles.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability necessitates immediate attention from security administrators. Organizations utilizing MarkLogic Server should verify their current version and apply the recommended patches immediately to prevent unauthorized privilege escalation and ensure the integrity of the Security database.