Incorrect authorization in MongoDB Server - CVE-2026-18690

 

Incorrect authorization in MongoDB Server - CVE-2026-18690

Published: August 18, 2026


Vulnerability identifier: #VU144146
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-18690
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform unauthorized actions on protected system collections.

The vulnerability exists due to improper authorization in protected system collections when handling actions from users with limited database-scoped roles. A remote user can perform actions against protected system collections to perform unauthorized actions on protected system collections.

This could result in critical system collections being dropped and recreated without proper authorization.


Affected software

MongoDB Server

How to mitigate CVE-2026-18690

Install security update from vendor's website.

MongoDB Server - addressed in versions 7.0.40, 8.0.29, 8.3.8

External References

Related Security Bulletins