An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progress
Progress marklogic Server |
|
| CPEs | cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Progress
Progress marklogic Server |
Fri, 07 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progress Software Corporation
Progress Software Corporation marklogic Server |
|
| Vendors & Products |
Progress Software Corporation
Progress Software Corporation marklogic Server |
Wed, 05 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database. | |
| Title | Privilege escalation in Progress MarkLogic Server Hadoop integration | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ProgressSoftware
Published: 2026-08-05T15:37:07.686Z
Updated: 2026-08-07T03:55:32.271Z
Reserved: 2026-05-21T15:19:27.735Z
Link: CVE-2026-9193
Updated: 2026-08-05T18:11:06.626Z
Status : Analyzed
Published: 2026-08-05T16:17:10.183
Modified: 2026-09-03T17:38:01.127
Link: CVE-2026-9193
No data.