SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82074

MEDIUM · CVSS 6.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

MongoDB Server is vulnerable due to an incorrect authorization issue in its aggregation framework, allowing authenticated users with minimal privileges to manipulate aggregation requests. This flaw can lead to unauthorized read access to sensitive collection data, potentially exposing confidential information. Organizations using MongoDB should prioritize addressing this vulnerability to mitigate risks associated with unauthorized data exposure.

CVE
CVE-2026-82074
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%
MongoDB

Original NVD Description

MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that causes the server's authorization subsystem to evaluate a different operation than what is actually executed, resulting in unauthorized read access to collection data within the target database.

Related CVEs

Other vulnerabilities affecting the same vendor(s)