top of page
perceptive_background_267k.jpg

An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows …

Published:

4 augustus 2026 om 22:00:00

Alert date:

5 augustus 2026 om 17:04:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Database & Storage, Identity & Access, Web Technologies

A critical improper privilege management vulnerability (CVE-2026-7329) has been identified in Progress MarkLogic Server affecting versions before 11.3.6 and 12.0.3. The flaw resides in the SQL, SPARQL, and Optic REST query interfaces. An authenticated user with only a low-privileged REST role can exploit this vulnerability to escalate privileges to administrator level. Once escalated, the attacker can execute privileged operations and gain unauthorized access to sensitive data. The vulnerability is classified as critical due to its potential for full administrative compromise. Affected organizations are advised to upgrade to MarkLogic Server 11.3.6 or 12.0.3 to remediate the issue. Progress has issued a security alert bulletin detailing the vulnerability and recommended mitigations.

Technical details

Mitigation steps:

Affected products:

Progress MarkLogic Server 11.x before 11.3.6
Progress MarkLogic Server 12.x before 12.0.3

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page