{"api_version":"1","generated_at":"2026-08-05T20:40:14+00:00","cve":"CVE-2026-9193","urls":{"html":"https://cve.report/CVE-2026-9193","api":"https://cve.report/api/cve/CVE-2026-9193.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-9193","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-9193"},"summary":{"title":"Privilege escalation in Progress MarkLogic Server Hadoop integration","description":"An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.","state":"PUBLISHED","assigner":"ProgressSoftware","published_at":"2026-08-05 16:17:10","updated_at":"2026-08-05 19:17:47"},"problem_types":["CWE-269","CWE-269 CWE-269: Improper Privilege Management"],"metrics":[{"version":"3.1","source":"security@progress.com","type":"Secondary","score":"9.9","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"9.9","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026","name":"https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026","refsource":"security@progress.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-9193","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9193","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Progress Software Corporation","product":"MarkLogic Server","version":"affected 11.0.0 11.3.6 custom","platforms":[]},{"source":"CNA","vendor":"Progress Software Corporation","product":"MarkLogic Server","version":"affected 12.0.0 12.0.3 custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"Restrict Hadoop integration privileges to users who require MLCP or Hadoop integration. Restrict network access to XDBC App Servers used for MLCP operations to trusted hosts. Disable XDBC App Servers used for MLCP if they are not required.","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"rexnets via Bugcrowd","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-9193","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-08-05T18:11:05.370202Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-05T18:41:51.324Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"MarkLogic Server","vendor":"Progress Software Corporation","versions":[{"lessThan":"11.3.6","status":"affected","version":"11.0.0","versionType":"custom"},{"lessThan":"12.0.3","status":"affected","version":"12.0.0","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"rexnets via Bugcrowd"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.</p>"}],"value":"An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-269","description":"CWE-269: Improper Privilege Management","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-05T15:37:07.686Z","orgId":"f9fea0b6-671e-4eea-8fde-31911902ae05","shortName":"ProgressSoftware"},"references":[{"tags":["vendor-advisory"],"url":"https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"}],"source":{"discovery":"EXTERNAL"},"title":"Privilege escalation in Progress MarkLogic Server Hadoop integration","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Restrict Hadoop integration privileges to users who require MLCP or Hadoop integration. Restrict network access to XDBC App Servers used for MLCP operations to trusted hosts. Disable XDBC App Servers used for MLCP if they are not required.</p>"}],"value":"Restrict Hadoop integration privileges to users who require MLCP or Hadoop integration. Restrict network access to XDBC App Servers used for MLCP operations to trusted hosts. Disable XDBC App Servers used for MLCP if they are not required."}],"x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"f9fea0b6-671e-4eea-8fde-31911902ae05","assignerShortName":"ProgressSoftware","cveId":"CVE-2026-9193","datePublished":"2026-08-05T15:37:07.686Z","dateReserved":"2026-05-21T15:19:27.735Z","dateUpdated":"2026-08-05T18:41:51.324Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-05 16:17:10","lastModifiedDate":"2026-08-05 19:17:47","problem_types":["CWE-269","CWE-269 CWE-269: Improper Privilege Management"],"metrics":{"cvssMetricV31":[{"source":"security@progress.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-05T18:11:05.370202Z","id":"CVE-2026-9193","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"9193","Ordinal":"1","Title":"Privilege escalation in Progress MarkLogic Server Hadoop integra","CVE":"CVE-2026-9193","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"9193","Ordinal":"1","NoteData":"An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.","Type":"Description","Title":"Privilege escalation in Progress MarkLogic Server Hadoop integra"}]}}}