CVE-2026-18704Patch(mongodb / mongodb)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mongodb mongodb systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify. This is due to an internal-use aggregation stage being reachable by external clients without an appropriate authorization check on its embedded operations.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mongodb

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
mongodb

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-15: 1Patch / Workaround · 2026-08-15: 1Technical Details · 2026-08-15: 108-15
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-18704 - Privilege escalation in MongoDB. Authenticated read-only users can perform unauthorized writes via aggregation framework. CVSS 6.5. No patch available. Restrict access and monitor. #CVE #MongoDB #infosec https://www.valtersit.com/cve/CVE-2026-18704 #CVE #infosec #SysAdmin #cybersecurity #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta

    Post summary

    The post discloses details about CVE-2026-18704, highlighting a privilege escalation vulnerability in MongoDB, notes that no patch exists, and recommends restricting access and monitoring as a workaround.

    0000052
    1.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmongodbmongodb---

Explore more