What is CVE-2026-18696?
A vulnerability in MongoDB Server's 'applyOps' command allows an authenticated user with specific non-default privileges to perform unauthorized data-definition operations (like dropping/modifying collections) due to an inconsistency in permission checking. Affected users are advised to update MongoDB to the latest patched version.
Azərbaycanca: MongoDB Server-in 'applyOps' əmrində müəyyən qeyri-standart imtiyazlara malik autentifikasiya olunmuş istifadəçiyə icazəsiz data-definition əməliyyatları (kolleksiyaları silmək/dəyişdirmək) icra etməyə imkan verən boşluq aşkarlanıb. Zəiflik icazə yoxlamasında uyğunsuzluqdan qaynaqlanır. Təsirə məruz qalan istifadəçilərə MongoDB-ni ən son yamaqlanmış versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: MongoDB
FAQ1
What type of unauthorized operations can a user with specific non-default privileges perform via the 'applyOps' command in MongoDB Server?
The vulnerability allows users with specific non-default privileges to perform unauthorized data-definition operations such as dropping or modifying collections.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.