


Perceptive Security
SOC/SIEM Consultancy

An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenti…
Published:
4 augustus 2026 om 22:00:00
Alert date:
5 augustus 2026 om 17:04:40
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access, Database & Storage, Web Technologies
A critical improper privilege management vulnerability (CVE-2026-8709) has been identified in Progress MarkLogic Server. The flaw exists in the REST API document patch operation and affects versions prior to 11.3.6 and 12.0.3. An authenticated user with a low-privileged REST role can exploit this vulnerability to escalate privileges. Successful exploitation allows the attacker to execute privileged operations against the Security database. This represents a significant risk as it enables unauthorized access to sensitive security configurations. Progress has issued a Critical Security Alert Bulletin in August 2026 addressing this issue. Users are urged to upgrade to the patched versions (11.3.6 or 12.0.3) immediately to mitigate exposure.
Technical details
Mitigation steps:
Affected products:
Progress MarkLogic Server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-8709
https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
