Sceawere

Vulnerability Detail

CVE-2026-18690UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MongoDB Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
5h ago
Vendor
MongoDB
Product
MongoDB Server
Attack Type
CWE-863: Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical system collections being dropped and recreated without proper authorization.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-11T19:17:22.757Z",
  "pubdate": "2026-08-11T19:17:22.757Z",
  "executiveSummary": "An authorization bypass vulnerability has been identified in MongoDB Server that affects the access control mechanisms governing protected system collections. This security flaw enables an authenticated user assigned a limited, database-scoped role to execute privileged operations against system-level collections that strictly exceed their intended authorization boundaries. The primary risk implication of this vulnerability involves severe integrity violations, specifically allowing unauthorized actors to drop and subsequently recreate critical system collections without proper validation or administrative oversight. Exploitation of this vulnerability requires prior authentication to the database system and possession of a constrained, database-scoped role, allowing low-privileged users to leverage insufficient permission enforcement to escalate their operational capabilities against core database structures.",
  "technicalDetails": "The root cause of this vulnerability lies in an authorization enforcement failure within MongoDB Server's access control subsystem when processing commands directed at protected system collections. Specifically, the privilege validation logic fails to adequately verify whether a user holding a restricted, database-scoped role possesses the requisite administrative permissions before permitting disruptive data definition language or administrative actions on sensitive namespaces.\nThe attack flow begins when an authenticated user with limited privileges crafts a database command designed to target protected system collections. Due to the flaw in privilege checking, the database engine improperly evaluates the caller's scoped context and evaluates the request as authorized. Consequently, the affected component executes the requested operation, permitting the unauthorized dropping of critical system collections. Following the deletion, the operational workflow allows the recreation of these collections under attacker-controlled parameters or in an unintended state.\nExploitation requirements necessitate that the threat actor is already authenticated to the target MongoDB Server instance and holds a limited database-scoped role. The vulnerability manifests locally through the database connection protocol interface utilized by authenticated clients. Post-exploitation impact is critical, as the unauthorized deletion and recreation of foundational system collections can lead to severe service disruption, data corruption, loss of metadata integrity, and potential denial of service across the affected database environment."
}
CVE-2026-18690: MongoDB Privilege Escalation Vulnerability (HIGH Severity, CVSS: 8.1) - Sceawere