CVE-2026-8709 PUBLISHED

Privilege escalation in Progress MarkLogic Server REST document patch operation

Assigner: ProgressSoftware
Reserved: 15.05.2026 Published: 05.08.2026 Updated: 05.08.2026

An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor Progress Software Corporation
Product MarkLogic Server
Versions Default: unaffected
  • affected from 11.0.0 to 11.3.6 (excl.)
  • affected from 12.0.0 to 12.0.3 (excl.)

Workarounds

Restrict REST API write privileges to accounts that require them. Review REST API service accounts and remove write access from accounts that do not require it.

Credits

  • rexnets via Bugcrowd finder

References

Problem Types

  • CWE-269: Improper Privilege Management CWE

Impacts

  • Privilege Escalation