← Back to CVE List
CVE-2026-8709NVD
Vulnerability Summary
An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.
CVSS v3.1 Base Metrics — Score 9.9 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Progress Marklogic Server < 11.3.6
- Progress Marklogic Server >= 12.0.0 and < 12.0.3
- Progress Marklogic Server 11.3.6
- Progress Marklogic Server 12.0.3