Executive brief
Progress MarkLogic Server is a database platform used to store and manage enterprise data. An improper privilege management flaw in the REST API allows authenticated administrative users to escalate their privileges and gain unauthorized access to sensitive server data that should only be accessible by higher-privileged accounts. This could expose confidential information such as customer records, financial data, or intellectual property.
Technical details
The vulnerability is an improper privilege management issue in the REST API document processing pipeline of MarkLogic Server. An authenticated user with an administrative REST role can exploit this flaw to escalate privileges beyond their intended authorization level. The attack requires prior authentication with an administrative REST role and is remotely exploitable via the REST API. A successful exploit allows an attacker to access sensitive data that should only be available to higher-privileged users. Patches are available in versions 11.3.6 and 12.0.3.
Affected products
- Progress MarkLogic Server before 11.3.6 and 12.0.3
Timeline
- 2026-08-05: disclosed