CVE-2026-7329 PUBLISHED

Privilege escalation in Progress MarkLogic Server REST query interfaces

Assigner: ProgressSoftware
Reserved: 28.04.2026 Published: 05.08.2026 Updated: 05.08.2026

An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor Progress Software Corporation
Product MarkLogic Server
Versions Default: unaffected
  • affected from 11.0.0 to 11.3.6 (excl.)
  • affected from 12.0.0 to 12.0.3 (excl.)

Workarounds

Restrict network access to REST query interfaces to trusted users and networks. Minimize assignment of REST roles.

Credits

  • 0xdln via Bugcrowd finder

References

Problem Types

  • CWE-269: Improper Privilege Management CWE

Impacts

  • Privilege Escalation