AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18698

MEDIUM · CVSS 5.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

MongoDB Server is vulnerable due to a flaw that permits authenticated users with limited database-scoped roles to access and potentially modify protected system collections without the necessary privileges. This could lead to unauthorized exposure of collection metadata and, in specific configurations, unauthorized alterations to system collection data. Organizations using MongoDB should prioritize addressing this vulnerability to safeguard their database integrity and prevent potential data breaches.

CVE
CVE-2026-18698
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%
MongoDB

Original NVD Description

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metadata and, on certain deployment configurations, unauthorized modification of system collection data.