Unauthorized Action Vulnerability in MongoDB Server
CVE-2026-18690
7.2HIGH
What is CVE-2026-18690?
A vulnerability in MongoDB Server allows authenticated users with restricted database roles to perform unauthorized actions on critical system collections. This issue can lead to the dropping and recreation of essential collections without proper privileges, potentially disrupting database integrity and security. Users should review their permissions and apply necessary patches to mitigate this risk.
Affected Version(s)
MongoDB Server 8.3.0 < 8.3.8
MongoDB Server 8.0 < 8.0.29
MongoDB Server 7.0 < 7.0.40