CVE-2026-18690Disclosure(mongodb / mongodb)

MEDIUMCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch mongodb mongodb systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical system collections being dropped and recreated without proper authorization.

4.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-863

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mongodb

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
mongodb

2 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-12: 1PoC Mentioned / Linked · 2026-08-12: 1Exploit Tool / Code · 2026-08-12: 1Patch / Workaround · 2026-08-12: 1Technical Details · 2026-08-12: 108-12
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • yousukezan@yousukezan
    Disclosure

    MongoDB Serverに、限定権限ユーザーが保護されたsystemコレクションへの認可を回避できる脆弱性CVE-2026-18690が見つかった。BSONのsymbol型でコレクション名を送ると、認可処理と実行処理で対象名前空間の解釈が食い違う。 問題は名前空間の解析処理にあり、先頭フィールドがString型でない場合、コレクション名を含まないデータベース単位の名前空間を返していた。symbol型は文字列と同じ内容を保持するが型が異なるため、認可側ではデータベース権限だけを確認し、実行側では実際のコレクションを対象に処理する。 研究者はMongoDB 8.0.28で、readWrite権限のappuserからsystem.viewsやsystem.profileへconvertToCappedを送り、通常の文字列ではUnauthorizedになる一方、symbol型では認可を通過してBadValueまで到達することを確認した。8.0.29では両方ともUnauthorizedとなった。 CVE-2026-18690は7.0.40、8.0.29、8.3.8で修正された。実際の悪用は確認されていない。 https://hellorecon.com/blog/cve-2026-18690-mongodb-symbol-type-authz-bypass

    Post summary

    CVE-2026-18690 is a MongoDB server authorization bypass that allows limited‑privilege users to access protected collections via symbol‑type collection names; a PoC is available, patches are released, and no active exploitation has been reported.

    010841.7K
    15.0K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appmongodbmongodb---
Appmongodbmongodb9.0.0--
Appmongodbmongodb9.0.0--
Appmongodbmongodb9.1.0--

Explore more