Privilege Escalation Vulnerability in Progress MarkLogic Server
CVE-2026-7329
9.9CRITICAL
What is CVE-2026-7329?
An improper privilege management vulnerability exists in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server. This flaw permits authenticated users with low-privileged REST roles to escalate their privileges to that of an administrator. Consequently, these users can execute privileged operations and gain unauthorized access to sensitive data, posing a significant risk to data integrity and security.
Affected Version(s)
MarkLogic Server 11.0.0 < 11.3.6
MarkLogic Server 12.0.0 < 12.0.3