CVE-2026-7327
HIGHPrivilege escalation in Progress MarkLogic Server REST API document processing
Title source: cnaDescription
An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is accessed by a higher-privileged user.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026
Scores
CVSS v3
8.1
EPSS
0.0022
EPSS Percentile
12.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-269
Status
published
Products (2)
Progress Software Corporation/MarkLogic Server
11.0.0 - 11.3.6
Progress Software Corporation/MarkLogic Server
12.0.0 - 12.0.3
Published
Aug 05, 2026
Tracked Since
Aug 05, 2026