Junglewise Threat Intelligence

CVE-2026-7329: Progress MarkLogic Server privilege escalation in query interfaces

CVE-2026-7329 · Severity: critical · CVSS 9.9 · Published 2026-08-05

Technologies: Progress Marklogic Server. Vendors: Progress.

Executive brief

Progress MarkLogic Server is a NoSQL database platform used for managing and querying complex data. A flaw in its SQL, SPARQL, and Optic REST query interfaces allows authenticated users with basic database access rights to gain full administrator privileges, enabling them to execute any operation and access sensitive data without proper authorization checks.

Technical details

This is an improper privilege management vulnerability affecting the SQL, SPARQL, and Optic REST query interfaces in Progress MarkLogic Server. An authenticated user possessing a low-privileged REST role can escalate privileges to administrator level. The vulnerability allows an attacker with network access and valid credentials (but limited permissions) to bypass authorization checks and execute privileged operations and access unauthorized data. Affected versions include those before 11.3.6 and 12.0.3. Patches are available in the fixed versions.

Affected products

  • Progress MarkLogic Server before 11.3.6 and 12.0.3

Timeline

  • 2026-08-05: disclosed

References

Related threats