Progress SoftwareCVE-2026-7329
Progress Software MarkLogic Server: privilege escalation
Critical9.9CVE-2026-7329 · Published Aug 5, 2026 · updated Sep 3, 2026
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| MarkLogic Server Product | >= 11.0.0, < 11.3.6 | 11.3.6 |
| >= 12.0.0, < 12.0.3 | 12.0.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-269
More Progress Software advisories
All Progress Software| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 5 | Progress Software MarkLogic Server: authentication bypass | Critical9.8 | 11.3.6+1 more |
| Aug 5 | Progress Software MarkLogic Server: privilege escalation | Critical9.9 | 11.3.6+1 more |
| Aug 5 | Progress Software MarkLogic Server: cross-site scripting | Critical9.3 | 11.3.6+1 more |
| Aug 5 | Progress Software MarkLogic Server: server-side request forgery | High8.5 | 11.3.6+1 more |
| Aug 5 | Progress Software MarkLogic Server: privilege escalation | High8.1 | 11.3.6+1 more |
| Aug 5 | Progress Software MarkLogic Server: authentication bypass | Critical9.1 | 11.3.6+1 more |