An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/SERVER-130139 |
|
History
Tue, 11 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation. | |
| Title | Improper Authorization in MongoDB applyOps Command Handling Allows Unauthorized DDL Operations on Collections | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published: 2026-08-11T18:40:35.414Z
Updated: 2026-08-11T20:23:36.869Z
Reserved: 2026-08-03T15:53:32.505Z
Link: CVE-2026-18696
Updated: 2026-08-11T20:23:32.586Z
Status : Received
Published: 2026-08-11T19:17:23.853
Modified: 2026-08-11T21:17:32.220
Link: CVE-2026-18696
No data.