An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical system collections being dropped and recreated without proper authorization.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/SERVER-130481 | Vendor Advisory Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
16 Sep 2026, 15:14
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Mongodb
Mongodb mongodb |
|
| CPE | cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:* cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:* cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:* cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* |
|
| References | () https://jira.mongodb.org/browse/SERVER-130481 - Vendor Advisory, Issue Tracking |
Information
Published : 2026-08-11 19:17
Updated : 2026-09-16 15:14
NVD link : CVE-2026-18690
Mitre link : CVE-2026-18690
CVE.ORG link : CVE-2026-18690
JSON object : View
Products Affected
mongodb
- mongodb
CWE
CWE-863
Incorrect Authorization
