CVE-2026-8709

marklogic_server: Improper Privilege Management (CVE-2026-8709)

criticalEPSS 0.5%

Affected

  • progress/marklogic_server lt *..11.3.6
  • progress/marklogic_server between 12.0.0..12.0.3

Description

An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

progressmarklogic_server
12.0.0 – 12.0.311.3.6fixed from 11.3.6

Metrics

9.9
Source: nvd-v3
38.2 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.5 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-05 15:33 UTC
CWE-269

Weakness classes (CWE)

  • CWE-269Class

    Improper Privilege Management

    The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Reanalysis2026-09-03 14:49 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:* versions from (including) 12.0.0 up to (excluding) 12.0.3 *cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:* versions from (including) 11.0.0 up to (excluding) 11.3.6 → OR *cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:* versions up to (excluding) 11.3.6 *cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:* versions from (including) 12.0.0 up to (excluding) 12.0.3
  2. Initial Analysis2026-09-03 13:57 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:* versions from (including) 12.0.0 up to (excluding) 12.0.3 *cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:* versions from (including) 11.0.0 up to (excluding) 11.3.6
    • Reference Type: Progress Software Corporation: https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026 Types: Vendor Advisory
  3. CVE Modified2026-08-07 05:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-8709","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalIm… → {"id":"CVE-2026-8709","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalIm…
  4. CVE Modified2026-08-05 19:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-8709","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalIm…
  5. New CVE Received2026-08-05 16:17 UTC· security@progress.com
    • Affected: MarkLogic Server
    • Description: An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
    • CWE: CWE-269

Linked advisories