Diagnostics Logging Modification Flaw in MongoDB Server by MongoDB
CVE-2026-18702

5.3MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
11 August 2026

What is CVE-2026-18702?

A flaw in MongoDB Server allows an authenticated user with limited database-scoped privileges to modify logging settings that impact the entire server. This can lead to the suppression of critical diagnostic logs, potentially masking unauthorized activities and hindering operational monitoring with excessive log generation. This vulnerability poses a significant risk to the integrity of monitoring processes and overall server security.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.8

MongoDB Server 8.0 < 8.0.29

MongoDB Server 7.0 < 7.0.40

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.