


Perceptive Security
SOC/SIEM Consultancy

An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows …
Published:
4 augustus 2026 om 22:00:00
Alert date:
5 augustus 2026 om 17:04:40
Source:
nvd.nist.gov
Enterprise Applications, Database & Storage, Identity & Access, Web Technologies
A critical improper privilege management vulnerability (CVE-2026-7329) has been identified in Progress MarkLogic Server affecting versions before 11.3.6 and 12.0.3. The flaw resides in the SQL, SPARQL, and Optic REST query interfaces. An authenticated user with only a low-privileged REST role can exploit this vulnerability to escalate privileges to administrator level. Once escalated, the attacker can execute privileged operations and gain unauthorized access to sensitive data. The vulnerability is classified as critical due to its potential for full administrative compromise. Affected organizations are advised to upgrade to MarkLogic Server 11.3.6 or 12.0.3 to remediate the issue. Progress has issued a security alert bulletin detailing the vulnerability and recommended mitigations.
Technical details
Mitigation steps:
Affected products:
Progress MarkLogic Server 11.x before 11.3.6
Progress MarkLogic Server 12.x before 12.0.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7329
https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
