Improper Privilege Management in Progress MarkLogic Server
CVE-2026-7327

8.1HIGH

Key Information:

Vendor
CVE Published:
5 August 2026

What is CVE-2026-7327?

An improper privilege management vulnerability exists in the REST API document processing pipeline of Progress MarkLogic Server versions prior to 11.3.6 and 12.0.3. This flaw allows authenticated users with an administrative REST role to exploit privilege escalation, which may lead to unauthorized access and disclosure of sensitive server-side data by higher-privileged users. It’s crucial for users of affected versions to apply updates promptly to mitigate the risk of potential data breaches.

Affected Version(s)

MarkLogic Server 11.0.0 < 11.3.6

MarkLogic Server 12.0.0 < 12.0.3

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rexnets via Bugcrowd
.