HIGH
Improper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Access to Protected View Data
Published Aug 11, 2026
7.1
HIGHCVSS 4.0
EPSS 0.36%
Description
An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process.
Affected products
-
Affected
- ≥ 7.0, < 7.0.40
- ≥ 8.0, < 8.0.29
- ≥ 8.3.0, < 8.3.8
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| MongoDB | MongoDB Server | unaffected | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56908 Advisory
- https://jira.mongodb.org/browse/SERVER-129618 Vendor AdvisoryIssue Tracking
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56908 | Advisory | |
| https://jira.mongodb.org/browse/SERVER-129618 | Vendor AdvisoryIssue Tracking |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mongodb
Published Aug 11, 2026
Updated Aug 11, 2026
Reserved Aug 3, 2026
Link CVE-2026-18705
CISA Vulnrichment
Updated Aug 11, 2026
Red Hat
No data
GitHub
No data