CVE-2026-9193 PUBLISHED

Privilege escalation in Progress MarkLogic Server Hadoop integration

Assigner: ProgressSoftware
Reserved: 21.05.2026 Published: 05.08.2026 Updated: 05.08.2026

An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor Progress Software Corporation
Product MarkLogic Server
Versions Default: unaffected
  • affected from 11.0.0 to 11.3.6 (excl.)
  • affected from 12.0.0 to 12.0.3 (excl.)

Workarounds

Restrict Hadoop integration privileges to users who require MLCP or Hadoop integration. Restrict network access to XDBC App Servers used for MLCP operations to trusted hosts. Disable XDBC App Servers used for MLCP if they are not required.

Credits

  • rexnets via Bugcrowd finder

References

Problem Types

  • CWE-269: Improper Privilege Management CWE