Improper privilege management in MongoDB Server - CVE-2026-18702
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to modify server-wide diagnostic logging settings.
The vulnerability exists due to improper privilege management in the profile command when handling requests to change diagnostic logging settings. A remote user can issue a crafted profile command to modify server-wide diagnostic logging settings.
This may suppress diagnostic logging across the server or cause excessive log volume that degrades operational monitoring.