CVE-2026-18704
Last modified
CVE-2026-18704 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify. This is due to an internal-use aggregation stage being reachable by external clients without an appropriate authorization check on its embedded operations..
Description
An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify. This is due to an internal-use aggregation stage being reachable by external clients without an appropriate authorization check on its embedded operations.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| MongoDB | MongoDB Server | >= 8.3.0, < 8.3.8 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-18704?
How severe is CVE-2026-18704?
How do I fix CVE-2026-18704?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18699An issue in MongoDB Server's query planner could allow an au…6.5
- CVE-2026-1870The Thim Kit for Elementor – Pre-built Templates & Widgets f…5.3
- CVE-2026-18700An issue in MongoDB Server's geospatial validation could all…6.5
- CVE-2026-18701An issue in MongoDB Server's query subsystem could allow an …7.1
- CVE-2026-18702An issue in MongoDB Server could allow an authenticated user…6.4
- CVE-2026-18703An issue in MongoDB Server could allow a party with a valid …4.2
- CVE-2026-18705An issue in MongoDB Server's Atlas Vector Search feature cou…7.1
- CVE-2026-18706An issue in MongoDB Server's $graphLookup aggregation stage …7.5
- CVE-2026-18707An issue in MongoDB Server could allow an authenticated user…5.3
- CVE-2026-18708An issue in MongoDB Server's JavaScript scripting engine cou…6.4
- CVE-2026-18709An issue in MongoDB Server could allow an authenticated user…6.4
- CVE-2026-1871TP-Link Tapo C200 v5 contains a stack-based buffer overflow …6.5
Are you affected by CVE-2026-18704?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
