PT-2026-70854 · Mongodb+1 · Mongodb Server+1

CVE-2026-18698

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MongoDB Server (affected versions not specified)
Description An issue allows an authenticated user with a limited database-scoped role to perform actions against protected system collections that normally require more specific privileges. This can lead to the exposure of collection metadata and, depending on the deployment configuration, the unauthorized modification of system collection data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18698

Affected Products

Mongodb Server
Mongodb