Junglewise Threat Intelligence

CVE-2026-18698: MongoDB Server privilege escalation via database-scoped role

CVE-2026-18698 · Severity: medium · CVSS 5.4 · Published 2026-08-11

Technologies: MongoDB Server. Vendors: MongoDB.

Executive brief

MongoDB Server contains an authentication bypass vulnerability that allows users with limited database-scoped roles to access protected system collections they should not have permission to reach. This could lead to unauthorized exposure of sensitive collection metadata or, in certain deployments, unauthorized modification of critical system data that governs database configuration and security.

Technical details

The vulnerability is a privilege escalation flaw in MongoDB Server's role-based access control (RBAC) system. An authenticated user with a limited database-scoped role can bypass authorization checks to access or modify protected system collections, which normally require higher-privilege roles or admin credentials. The attack is network-accessible and requires only valid (but limited) database credentials. An authenticated attacker can read sensitive system metadata and potentially modify system collection data, depending on the deployment configuration. Patches are available in versions 7.0.40, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2, and 9.1.0-rc0.

Affected products

  • MongoDB Server before 7.0.40, before 8.0.29, before 8.2.13, before 8.3.8, before 9.0.0-rc2, before 9.1.0-rc0

Timeline

  • 2026-08-11: disclosed: CVE-2026-18698 published
  • 2026-08-11: patched: Patches released in versions 7.0.40, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2, 9.1.0-rc0

References