AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-7327

HIGH · CVSS 8.1 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

An improper privilege management vulnerability in the REST API of Progress MarkLogic Server prior to versions 11.3.6 and 12.0.3 allows authenticated users with administrative REST roles to escalate their privileges. This can lead to unauthorized access to sensitive server-side data by higher-privileged users, posing a significant risk to data confidentiality. Organizations using affected versions should prioritize patching to mitigate potential data breaches.

CVE
CVE-2026-7327
Severity
HIGH
CVSS
8.1
EPSS
0.22%

Original NVD Description

An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is accessed by a higher-privileged user.