Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic.
To remediate this issue, users should upgrade to version 1.0.12 or later.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic. To remediate this issue, users should upgrade to version 1.0.12 or later. | |
| Title | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server | |
| First Time appeared |
Aws
Aws documentdb-mcp-server |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:aws:documentdb-mcp-server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws documentdb-mcp-server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-08-05T20:07:35.451Z
Reserved: 2026-08-05T13:45:00.654Z
Link: CVE-2026-18954
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T21:45:04Z