CVE-2026-9193: Privilege escalation in Progress MarkLogic Server Hadoop integration
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9193?
The severity of CVE-2026-9193 is critical, with a score of 9.9.
How do I fix CVE-2026-9193?
To fix CVE-2026-9193, upgrade Progress MarkLogic Server to version 11.3.6 or 12.0.3 or later.
What type of vulnerability is CVE-2026-9193?
CVE-2026-9193 is a privilege escalation vulnerability in the Hadoop integration of Progress MarkLogic Server.
Who is affected by CVE-2026-9193?
Authenticated users with low-privileged Hadoop roles in Progress MarkLogic Server prior to the fixed versions are affected by CVE-2026-9193.
What can attackers achieve with CVE-2026-9193?
Attackers can escalate privileges and execute unauthorized privileged operations against the Security database with CVE-2026-9193.