External risk intelligence

Progress MarkLogic Hadoop Integration Privilege Escalation Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-9193

This vulnerability affects the Hadoop integration component within a database server. While network-reachable in some enterprise environments, database integration layers are typically deployed within internal network segments and are not intended for direct public internet exposure.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in Progress MarkLogic Server's Hadoop integration allows authenticated users with limited Hadoop roles to gain elevated privileges and perform sensitive operations within the Security database. This means a user with low-level access could potentially compromise critical security settings if this specific integration is in use. The primary concern is to confirm if this component is relevant to your environment and assess any exposure.

  • Low-privilege users can gain administrative control.
  • Matters if you use Hadoop with MarkLogic Server.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can leverage this vulnerability by first gaining authenticated access to the MarkLogic Server with a low-privileged Hadoop role. Once authenticated, they can exploit the improper privilege management in the Hadoop integration to escalate their privileges. This allows them to perform sensitive operations on the Security database, potentially leading to a complete compromise of the system's security.

  • Authenticated low-privileged user access required.
  • Improper privilege management in Hadoop integration.
  • Privilege escalation to control security data.

Live Threat

Current exploitation, exposure, and threat context

An improper privilege management vulnerability in MarkLogic Server's Hadoop integration could allow an authenticated user with a low-privileged Hadoop role to perform privileged operations against the Security database. This may occur when the Hadoop integration is enabled and configured.

  • Security database.
  • Low-privileged user escalates privileges.
  • Unauthorized privileged operations.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Progress MarkLogic Server's Hadoop integration, suggesting that the application owners and the infrastructure or platform teams responsible for managing MarkLogic and its Hadoop components should collaborate on remediation. The initial step is to identify all instances of the affected MarkLogic Server, determine their network exposure, assess their business criticality, and assign an owner for tracking and resolution.

  • Application and platform teams own this.
  • Verify MarkLogic instances and Hadoop integration.
  • Plan remediation based on exposure and criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Progress MarkLogic Server and its Hadoop integration?

Progress MarkLogic is a multi-model database used for complex data integration and search. The Hadoop integration allows the database to process, ingest, or export large datasets stored in Hadoop Distributed File Systems. Organizations typically use this feature to bridge analytical workloads with operational data, enabling users to run Hadoop-related tasks directly within their MarkLogic environment.

What does CWE-269 mean for CVE-2026-9193?

CWE-269 refers to improper privilege management. In the context of CVE-2026-9193, it means the software fails to correctly restrict what a user can do based on their assigned role. Normally, a user with limited Hadoop-specific permissions should not have the power to change security settings. This flaw allows that user to bypass these restrictions, essentially granting themselves administrative-level authority.

How is this vulnerability triggered?

An attacker must already have authenticated access to the MarkLogic Server as a user with a low-privileged Hadoop role. The vulnerability is not triggered by unauthenticated users or simple internet browsing; it requires a valid, albeit limited, login. If the Hadoop integration is disabled or not configured, this specific path to escalating privileges to the Security database does not exist.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal notes that while this is a network-based vulnerability, database integration layers like Hadoop connectors are usually kept within internal network segments rather than on the public internet. This makes direct exposure unlikely for most systems. You should prioritize checking internal access controls to ensure that only trusted users have the Hadoop roles required to attempt this.

Do I need to update my MarkLogic environment immediately?

Your first step is to inventory your systems to identify where MarkLogic is running and whether the Hadoop integration feature is active. Since this is a critical issue, collaborate with your platform teams to confirm if the specific versions 11.3.6 or 12.0.3 are in use. If they are, planning an upgrade is the recommended path to resolve the privilege management flaw.

References