CVE-2026-18712

An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different collection. This is due to insufficient validation of certain internal metadata references before they are used to perform operations on other namespaces.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-11 19:17

Updated : 2026-08-28 21:16


NVD link : CVE-2026-18712

Mitre link : CVE-2026-18712

CVE.ORG link : CVE-2026-18712


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization