CVE-2026-82074

MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that causes the server's authorization subsystem to evaluate a different operation than what is actually executed, resulting in unauthorized read access to collection data within the target database.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-132275 Vendor Advisory Issue Tracking
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*

History

16 Sep 2026, 20:39

Type Values Removed Values Added
References () https://jira.mongodb.org/browse/SERVER-132275 - () https://jira.mongodb.org/browse/SERVER-132275 - Vendor Advisory, Issue Tracking
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
First Time Mongodb
Mongodb mongodb

Information

Published : 2026-09-08 17:18

Updated : 2026-09-16 20:39


NVD link : CVE-2026-82074

Mitre link : CVE-2026-82074

CVE.ORG link : CVE-2026-82074


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-863

Incorrect Authorization