Reliance on Untrusted Inputs in a Security Decision in MongoDB Server - CVE-2026-18705

 

Reliance on Untrusted Inputs in a Security Decision in MongoDB Server - CVE-2026-18705

Published: August 18, 2026


Vulnerability identifier: #VU144135
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-18705
CWE-ID: CWE-807
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to reliance on untrusted inputs in a security decision in Atlas Vector Search when constructing an internal request forwarded to the search process. A remote user can supply crafted fields to retrieve documents from a different protected view to disclose sensitive information.

Exploitation requires read access to one view, and the exposed data comes from another protected view over the same underlying collection.


Affected software

MongoDB Server

How to mitigate CVE-2026-18705

Install security update from vendor's website.

MongoDB Server - addressed in versions 7.0.40, 8.0.29, 8.3.8

External References

Related Security Bulletins