top of page
perceptive_background_267k.jpg

An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows …

Published:

4 August 2026 at 22:00:00

Alert date:

5 August 2026 at 17:04:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Database & Storage, Identity & Access, Web Technologies

A critical improper privilege management vulnerability (CVE-2026-7329) has been identified in Progress MarkLogic Server affecting versions before 11.3.6 and 12.0.3. The flaw resides in the SQL, SPARQL, and Optic REST query interfaces. An authenticated user with only a low-privileged REST role can exploit this vulnerability to escalate privileges to administrator level. Once escalated, the attacker can execute privileged operations and gain unauthorized access to sensitive data. The vulnerability is classified as critical due to its potential for full administrative compromise. Affected organizations are advised to upgrade to MarkLogic Server 11.3.6 or 12.0.3 to remediate the issue. Progress has issued a security alert bulletin detailing the vulnerability and recommended mitigations.

Technical details

Mitigation steps:

Affected products:

Progress MarkLogic Server 11.x before 11.3.6
Progress MarkLogic Server 12.x before 12.0.3

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page