What is CVE-2026-18704?
CVE-2026-18704 is a critical flaw in MongoDB Server's aggregation framework where an authenticated user with read-only privileges can perform write operations on collections they shouldn't modify, due to an internal-use aggregation stage being reachable by external clients. This leads to privilege escalation. It is recommended to monitor MongoDB's official updates for a patch.
Azərbaycanca: CVE-2026-18704 MongoDB Server-in aggregation framework-də kritik zəiflikdir. Autentifikasiya olunmuş, yalnız oxuma hüququ olan istifadəçi xüsusi aggregation stage vasitəsilə aid olmayan kolleksiyalara yazma əməliyyatı icra edə bilər, bu səlahiyyət yüksəlişinə səbəb olur. Ətraflı məlumat üçün MongoDB-nin rəsmi yeniləmələrini izləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: MongoDB
FAQ2
Which MongoDB component does CVE-2026-18704 affect?
This vulnerability affects the aggregation framework of MongoDB Server.
How can an attacker achieve privilege escalation via CVE-2026-18704?
An authenticated user with read-only privileges can perform write operations on collections they shouldn't modify by using a specific aggregation stage.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.