Reliance on Untrusted Inputs in a Security Decision in MongoDB Server - CVE-2026-18705
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to reliance on untrusted inputs in a security decision in Atlas Vector Search when constructing an internal request forwarded to the search process. A remote user can supply crafted fields to retrieve documents from a different protected view to disclose sensitive information.
Exploitation requires read access to one view, and the exposed data comes from another protected view over the same underlying collection.