Junglewise Threat Intelligence

CVE-2026-18702: MongoDB Server privilege escalation in logging settings

CVE-2026-18702 · Severity: medium · CVSS 6.4 · Published 2026-08-11

Technologies: MongoDB Server. Vendors: MongoDB.

Executive brief

MongoDB Server contains a privilege escalation flaw that allows a database user with limited permissions to modify server-wide diagnostic logging settings. An attacker could suppress logging across the entire server to hide unauthorized activities, or cause excessive logging to degrade operational monitoring and system performance.

Technical details

A privilege escalation vulnerability in MongoDB Server's profiling command (specifically the slowms and sampleRate parameters) allows an authenticated user with database-scoped privileges to modify diagnostic logging settings at the server level. The root cause is insufficient privilege validation that fails to restrict scope properly during parameter modification. The attacker must be an authenticated database user, and the attack occurs over the network via the profiling command. Exploitation allows modification of server-wide logging configuration from limited database-level credentials, enabling log suppression or manipulation. Patches are available in versions 7.0.40, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2, and 9.1.0-rc0.

Affected products

  • MongoDB Server before 7.0.40, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2, 9.1.0-rc0

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: patched: Patches released for versions 7.0.40, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2, 9.1.0-rc0

References