An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metadata and, on certain deployment configurations, unauthorized modification of system collection data.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/SERVER-130481 |
|
History
Tue, 11 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metadata and, on certain deployment configurations, unauthorized modification of system collection data. | |
| Title | Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections via the validate Command | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-08-11T20:19:55.434Z
Reserved: 2026-08-03T15:53:35.403Z
Link: CVE-2026-18698
Updated: 2026-08-11T20:19:51.313Z
Status : Received
Published: 2026-08-11T19:17:24.120
Modified: 2026-08-11T21:17:32.443
Link: CVE-2026-18698
No data.
OpenCVE Enrichment
No data.