Back

HIGH

Incorrect Authorization in MongoDB Server Aggregation Framework Allows Unauthorized Read Access to Collection Data

Published Sep 8, 2026

Description

MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that causes the server's authorization subsystem to evaluate a different operation than what is actually executed, resulting in unauthorized read access to collection data within the target database.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mongodb
Published Sep 8, 2026
Updated Sep 8, 2026
Reserved Aug 27, 2026
CISA Vulnrichment
Updated Sep 8, 2026
NVD
Status Analyzed
Modified Sep 16, 2026
Red Hat
Severity n/a
Public date n/a