CRITICALVulnerability

CVE-2026-8709

An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.

Properties

severity
CRITICAL
score
9.9
cve_id
CVE-2026-8709
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
published_at
2026-08-05T16:17:09.820
last_modified
2026-08-28T21:16:15.740

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Privilege Management

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-8709 — Ninja Signal Threat Intelligence | Ninja Signal