A critical privilege escalation vulnerability has been identified in Progress MarkLogic Server versions prior to 11.3.6 and 12.0.3. The vulnerability exists within the REST API document patch operation, enabling an authenticated user with a low-privileged REST role to execute privileged operations against the Security database. This allows unauthorized access to sensitive system functions and data, posing a significant risk to affected deployments. Organizations utilizing these versions of MarkLogic Server are strongly advised to apply the latest security patches immediately to mitigate exploitation risks. The CVSS score of 9.9 reflects the high severity of this issue, emphasizing the urgency of remediation. Attackers could exploit this vulnerability to bypass access controls, potentially leading to data breaches, system compromise, or disruption of services. As this vulnerability requires authentication, it is recommended to review and restrict REST API access to only necessary users and roles until patches are applied. This advisory underscores the importance of timely patch management and continuous monitoring of security updates for critical infrastructure components.