Executive brief
Progress MarkLogic Server is an enterprise NoSQL database platform used for managing and searching unstructured data. A vulnerability in its Hadoop integration allows an authenticated user with limited Hadoop permissions to escalate privileges and execute restricted operations against the Security database, potentially leading to unauthorized access to sensitive data or system configuration changes.
Technical details
This is an improper privilege management vulnerability (CWE-269) in the Hadoop integration component of MarkLogic Server. An authenticated attacker with a low-privileged Hadoop role can escalate privileges to perform administrative operations against the Security database. The vulnerability requires prior authentication but does not require network-based exploitation from an unauthenticated state. Successful exploitation allows an insider or compromised Hadoop user to bypass access controls and execute privileged database operations. The vulnerability is fixed in versions 11.3.6 and 12.0.3 or later.
Affected products
- Progress MarkLogic Server before 11.3.6 and 12.0.3
Timeline
- 2026-08-05: disclosed