Back

HIGH

Improper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Access to Protected View Data

Published Aug 11, 2026

Description

An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mongodb
Published Aug 11, 2026
Updated Aug 11, 2026
Reserved Aug 3, 2026

CISA Vulnrichment

Updated Aug 11, 2026

NVD

Status Analyzed
Modified Sep 16, 2026

Red Hat

No data

ENISA EUVD

Assigner mongodb
Published Aug 11, 2026
Updated Aug 11, 2026

GitHub

No data