An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/SERVER-129618 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-11 19:17
Updated : 2026-08-28 21:16
NVD link : CVE-2026-18705
Mitre link : CVE-2026-18705
CVE.ORG link : CVE-2026-18705
JSON object : View
Products Affected
No product.
CWE
CWE-807
Reliance on Untrusted Inputs in a Security Decision
