What is CVE-2026-18690?
A vulnerability in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform unauthorized actions on protected system collections. This may lead to critical system collections being dropped and recreated without proper permissions.
Azərbaycanca: MongoDB Server-də autentifikasiya olunmuş məhdud verilənlər bazası əhatəli istifadəçinin qorunan sistem kolleksiyalarına icazəsiz əməliyyatlar icra etməsinə imkan verən boşluq aşkarlanıb. Bu, kritik sistem kolleksiyalarının silinməsinə və düzgün icazələr olmadan yenidən yaradılmasına səbəb ola bilər.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: MongoDB
FAQ2
Does exploiting CVE-2026-18690 require authentication?
Yes, the vulnerability can only be exploited by an authenticated user with a limited database-scoped role.
What critical outcome can this vulnerability cause in MongoDB?
The vulnerability may lead to protected system collections being dropped and recreated without the proper permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.