AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18705

MEDIUM · CVSS 6.5 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

MongoDB's Atlas Vector Search feature is vulnerable, allowing authenticated users with read access to one view to access documents from another protected view within the same collection due to inadequate handling of user-supplied fields. This could lead to unauthorized data exposure, compromising sensitive information. Organizations using MongoDB, particularly those leveraging the Atlas Vector Search feature, should prioritize addressing this vulnerability to safeguard their data integrity.

CVE
CVE-2026-18705
Severity
MEDIUM
CVSS
6.5
EPSS
0.27%
MongoDB

Original NVD Description

An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process.