Improper privilege management in MarkLogic - CVE-2026-8709
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper privilege management in the REST document patch operation when processing document patch requests. A remote user can exploit the patch operation to escalate privileges.
This enables execution of privileged operations against the Security database.