CVE-2026-9193
marklogic_server: Improper Privilege Management (CVE-2026-9193)
criticalEPSS 0.5%
Affected
- progress/marklogic_server
lt *..11.3.6 - progress/marklogic_server
between 12.0.0..12.0.3
Description
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.
Source: NVD (NIST)cvelistv5
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
progressmarklogic_server
12.0.0 – 12.0.311.3.6fixed from 11.3.6Metrics
Show all metrics
Severity
critical
85.47
no public PoC known
9.9
Published
2026-08-05 15:37 UTC
CWE-269
Weakness classes (CWE)
CWE-269Class
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-09-03 17:38 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:* versions up to (excluding) 11.3.6 *cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:* versions from (including) 12.0.0 up to (excluding) 12.0.3
- Reference Type: Progress Software Corporation: https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026 Types: Vendor Advisory
- CVE Modified2026-08-07 05:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-9193","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalIm… → {"id":"CVE-2026-9193","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalIm…
- CVE Modified2026-08-05 19:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-9193","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalIm…
- New CVE Received2026-08-05 16:17 UTC· security@progress.com
- Affected: MarkLogic Server
- Description: An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.
- CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- CWE: CWE-269