AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18702

MEDIUM · CVSS 6.4 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

MongoDB Server is vulnerable, allowing authenticated users with limited database-scoped privileges to alter diagnostic logging settings across the entire server. This could lead to the suppression of critical logs, obscuring unauthorized activities, or result in excessive log generation that hampers operational monitoring. Organizations using MongoDB should prioritize addressing this vulnerability to maintain proper oversight and security of their database environments.

CVE
CVE-2026-18702
Severity
MEDIUM
CVSS
6.4
EPSS
0.21%
MongoDB

Original NVD Description

An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the intended database. This could allow suppression of diagnostic logging server-wide, potentially obscuring unauthorized activity, or degrade operational monitoring by causing excessive log volume.