An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metadata and, on certain deployment configurations, unauthorized modification of system collection data.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/SERVER-130481 | Vendor Advisory Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
16 Sep 2026, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Mongodb
Mongodb mongodb |
|
| References | () https://jira.mongodb.org/browse/SERVER-130481 - Vendor Advisory, Issue Tracking | |
| CPE | cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:* cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:* cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:* cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* |
Information
Published : 2026-08-11 19:17
Updated : 2026-09-16 15:17
NVD link : CVE-2026-18698
Mitre link : CVE-2026-18698
CVE.ORG link : CVE-2026-18698
JSON object : View
Products Affected
mongodb
- mongodb
CWE
CWE-863
Incorrect Authorization
