An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.
https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026