Incorrect authorization in MongoDB Server - CVE-2026-18712
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to modify or destroy data in a different collection.
The vulnerability exists due to improper authorization in Queryable Encryption maintenance operations when processing internal metadata references for operations on other namespaces. A remote user can manipulate certain metadata references to modify or destroy data in a different collection.
Exploitation requires privileges on one encrypted collection.