PT-2026-70847 · Mongodb · Mongodb Server

CVE-2026-18690

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions MongoDB Server (affected versions not specified)
Description An issue allows an authenticated user with a limited database-scoped role to perform unauthorized actions against protected system collections. This flaw could enable the dropping and recreation of critical system collections, bypassing the restrictions of the user's assigned privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18690

Affected Products

Mongodb Server