Junglewise Threat Intelligence

CVE-2026-18954: Amazon AWS Labs DocumentDB MCP Server authorization bypass in aggregation pipeline

CVE-2026-18954 · Severity: high · Published 2026-09-09

Executive brief

Amazon AWS Labs DocumentDB Model Context Protocol (MCP) Server contains an authorization flaw in its aggregation pipeline tool that allows attackers to bypass access controls. This could enable unauthorized users to access or manipulate data within DocumentDB databases, potentially exposing sensitive information or causing data integrity issues.

Technical details

CVE-2026-18954 is an authorization bypass vulnerability in the aggregation pipeline tool component of AWS Labs DocumentDB MCP Server. The vulnerability stems from incorrect authorization checks that fail to properly validate user permissions before allowing aggregation pipeline operations. An attacker with network access to the MCP Server can exploit this flaw to execute unauthorized aggregation operations against DocumentDB databases, potentially reading sensitive data or modifying query results. The vulnerability affects the AWS Labs DocumentDB MCP Server; patch availability and specific version ranges have not been disclosed in available advisories.

Affected products

  • Amazon AWS Labs DocumentDB MCP Server <UNKNOWN>

Timeline

  • 2026-09-09: disclosed

References

Related threats