AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-8709

CRITICAL · CVSS 9.9 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server allows authenticated users with low-privileged roles to escalate their privileges and perform unauthorized actions on the Security database. This critical flaw, rated 9.9 on the CVSS scale, poses a significant risk to organizations using affected versions prior to 11.3.6 and 12.0.3. Administrators and security teams should prioritize remediation to prevent potential exploitation and unauthorized access to sensitive data.

CVE
CVE-2026-8709
Severity
CRITICAL
CVSS
9.9
EPSS
0.26%

Original NVD Description

An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.