CVE-2026-9193: An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Ha
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-9193
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-9193 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for An improper privilege
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-8709: An improper privilege management vulnerability in the REST API document patch operation of Prog…nvd · 2026-08-05
- criticalCVE-2026-7329: An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfa…nvd · 2026-08-05
- highCVE-2026-7327: An improper privilege management vulnerability in the REST API document processing pipeline of …nvd · 2026-08-05
- unknownCVE-2026-15587: Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Go…nvd · 2026-08-05
- highCVE-2026-59912: Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Impro…nvd · 2026-08-03
- mediumCVE-2026-40717: Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access …nvd · 2026-08-03
More from NVD Recent CVEs
- highCVE-2026-9203: A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0…2026-08-05
- criticalCVE-2026-9195: A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 1…2026-08-05
- criticalCVE-2026-9192: An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server befo…2026-08-05
- criticalCVE-2026-9190: An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server bef…2026-08-05
- criticalCVE-2026-8709: An improper privilege management vulnerability in the REST API document patch operation of Prog…2026-08-05