CVE-2026-18705

An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-11 19:17

Updated : 2026-08-28 21:16


NVD link : CVE-2026-18705

Mitre link : CVE-2026-18705

CVE.ORG link : CVE-2026-18705


JSON object : View

Products Affected

No product.

CWE
CWE-807

Reliance on Untrusted Inputs in a Security Decision