MongoDBCVE-2026-18698
MongoDB Server: improper authorization
Medium5.3CVE-2026-18698 · Published Aug 11, 2026 · updated Sep 16, 2026
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metadata and, on certain deployment configurations, unauthorized modification of system collection data.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| MongoDB Server Product | >= 8.3.0, < 8.3.8 | 8.3.8 |
| >= 8.0, < 8.0.29 | 8.0.29 | |
| >= 7.0, < 7.0.40 | 7.0.40 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More MongoDB advisories
All MongoDB| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | Cleartext Storage of Sensitive Information in MongoDB Driver Logging During Client Initialization | Medium6.5 | 5.9.2+1 more |
| Aug 11 | MongoDB Server: improper authorization | High7.2 | 8.3.8+2 more |
| Aug 11 | MongoDB Server: use after free | High7.1 | 8.3.8+1 more |
| Aug 11 | MongoDB Server: missing authorization | High7.1 | 8.3.8 |
| Aug 11 | MongoDB Server: untrusted input in a security decision | High7.1 | 8.3.8+2 more |
| Aug 11 | MongoDB Server: use after free | High7.5 | 8.3.8 |