Authorization Flaw in AWS DocumentDB MCP Server
CVE-2026-18954
5.7MEDIUM
What is CVE-2026-18954?
An authorization flaw in the aggregation pipeline tool of Amazon's AWS DocumentDB MCP Server prior to version 1.0.12 allows authenticated MCP clients to exploit write-capable stages, potentially bypassing the intended read-only mode. This vulnerability permits unauthorized write operations on connected databases, raising significant concerns over data integrity and security. Users are strongly advised to upgrade to version 1.0.12 or later to mitigate these risks.
Affected Version(s)
documentdb-mcp-server 0 < 1.0.12
