What is CVE-2026-18702?
CVE-2026-18702 is a vulnerability in MongoDB Server where an authenticated user with limited, database-scoped privileges can modify diagnostic logging settings affecting the entire server. This may allow server-wide suppression of diagnostic logging, potentially obscuring unauthorized activities. Affected MongoDB deployments should be patched immediately.
Azərbaycanca: CVE-2026-18702 MongoDB Server-də autentifikasiya olunmuş, məhdud verilənlər bazası səlahiyyətlərinə malik istifadəçiyə bütün serverə təsir edən diaqnostik logging parametrlərini dəyişməyə imkan verən qüsurdur. Bu, icazəsiz hərəkətləri gizlətmək məqsədilə server miqyasında diaqnostik qeydlərin bloklanmasına səbəb ola bilər. Təsirə məruz qalan sistemlərdə dərhal MongoDB tərəfindən təqdim edilən təhlükəsizlik yaması tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-269
FAQ1
What privileges must an attacker have to exploit CVE-2026-18702?
To exploit this vulnerability, the attacker must be an authenticated user with limited, database-scoped privileges on MongoDB Server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.