Executive brief
MongoDB Server contains an authentication bypass vulnerability that allows users with limited database-scoped roles to access protected system collections they should not have permission to reach. This could lead to unauthorized exposure of sensitive collection metadata or, in certain deployments, unauthorized modification of critical system data that governs database configuration and security.
Technical details
The vulnerability is a privilege escalation flaw in MongoDB Server's role-based access control (RBAC) system. An authenticated user with a limited database-scoped role can bypass authorization checks to access or modify protected system collections, which normally require higher-privilege roles or admin credentials. The attack is network-accessible and requires only valid (but limited) database credentials. An authenticated attacker can read sensitive system metadata and potentially modify system collection data, depending on the deployment configuration. Patches are available in versions 7.0.40, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2, and 9.1.0-rc0.
Affected products
- MongoDB Server before 7.0.40, before 8.0.29, before 8.2.13, before 8.3.8, before 9.0.0-rc2, before 9.1.0-rc0
Timeline
- 2026-08-11: disclosed: CVE-2026-18698 published
- 2026-08-11: patched: Patches released in versions 7.0.40, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2, 9.1.0-rc0