CVE-2026-7329

CRITICAL

Privilege escalation in Progress MarkLogic Server REST query interfaces

Title source: cna
STIX 2.1

Description

An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.

References (1)

Core 1

Scores

CVSS v3 9.9
EPSS 0.0032
EPSS Percentile 24.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (2)
Progress Software Corporation/MarkLogic Server 11.0.0 - 11.3.6
Progress Software Corporation/MarkLogic Server 12.0.0 - 12.0.3
Published Aug 05, 2026
Tracked Since Aug 05, 2026