Improper privilege management in MarkLogic - CVE-2026-7327
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive server-side data.
The vulnerability exists due to improper privilege management in the REST API document processing pipeline when processing documents through the REST API. A remote user can exploit the flaw to disclose sensitive server-side data.
Exploitation requires access by a higher-privileged user to the affected content.