Executive brief
Progress MarkLogic Server is an enterprise NoSQL database platform. A vulnerability in its REST API document patch operation allows low-privileged users to escalate privileges and execute restricted operations against the security database, enabling unauthorized access to sensitive data and administrative functions.
Technical details
This is an improper privilege management vulnerability in the REST API document patch operation of MarkLogic Server. An authenticated user with a low-privileged REST role can exploit insufficient authorization checks in the patch endpoint to escalate privileges and perform restricted operations against the Security database. The attack requires network access and valid authentication credentials but no additional user interaction. An attacker can bypass role-based access controls to execute privileged operations they should not have permission to perform. Patches are available in MarkLogic Server 11.3.6 and 12.0.3 or later.
Affected products
- Progress MarkLogic Server before 11.3.6 and before 12.0.3
Timeline
- 2026-08-05: disclosed