{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-9193",
        "assignerOrgId": "f9fea0b6-671e-4eea-8fde-31911902ae05",
        "state": "PUBLISHED",
        "assignerShortName": "ProgressSoftware",
        "dateReserved": "2026-05-21T15:19:27.735Z",
        "datePublished": "2026-08-05T15:37:07.686Z",
        "dateUpdated": "2026-08-07T03:55:32.271Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "f9fea0b6-671e-4eea-8fde-31911902ae05",
                "shortName": "ProgressSoftware",
                "dateUpdated": "2026-08-05T15:37:07.686Z"
            },
            "title": "Privilege escalation in Progress MarkLogic Server Hadoop integration",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-269",
                            "description": "CWE-269: Improper Privilege Management",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Progress Software Corporation",
                    "product": "MarkLogic Server",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "11.0.0",
                            "lessThan": "11.3.6",
                            "versionType": "custom"
                        },
                        {
                            "status": "affected",
                            "version": "12.0.0",
                            "lessThan": "12.0.3",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026",
                    "tags": [
                        "vendor-advisory"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "LOW",
                        "userInteraction": "NONE",
                        "scope": "CHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "HIGH",
                        "baseSeverity": "CRITICAL",
                        "baseScore": 9.9,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
                    }
                }
            ],
            "workarounds": [
                {
                    "lang": "en",
                    "value": "Restrict Hadoop integration privileges to users who require MLCP or Hadoop integration. Restrict network access to XDBC App Servers used for MLCP operations to trusted hosts. Disable XDBC App Servers used for MLCP if they are not required.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>Restrict Hadoop integration privileges to users who require MLCP or Hadoop integration. Restrict network access to XDBC App Servers used for MLCP operations to trusted hosts. Disable XDBC App Servers used for MLCP if they are not required.</p>"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "rexnets via Bugcrowd",
                    "type": "finder"
                }
            ],
            "source": {
                "discovery": "EXTERNAL"
            },
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-08-06T00:00:00+00:00",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3",
                                "id": "CVE-2026-9193"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-08-07T03:55:32.271Z"
                }
            }
        ]
    }
}