What is CVE-2026-18705?
CVE-2026-18705 is a vulnerability in MongoDB Server's Atlas Vector Search feature where an authenticated user with read access to one view can retrieve documents from a different, protected view over the same underlying collection. This occurs due to insufficient handling of certain user-supplied fields during query construction, potentially leading to unauthorized data exposure. Applying the security patches released by MongoDB is recommended.
Azərbaycanca: CVE-2026-18705: MongoDB Server-in Atlas Vector Search funksiyasında autentifikasiya olunmuş istifadəçinin bir view üzərində oxuma icazəsi ilə eyni kolleksiyadakı digər qorunan view-dən sənədləri əldə etməsinə imkan verən zəiflikdir. İstifadəçi tərəfindən təqdim olunan sahələrin düzgün idarə edilməməsi səbəbindən baş verir və məlumat sızmasına yol aça bilər. Təsirə məruz qalan sistemlərdə MongoDB tərəfindən buraxılan təhlükəsizlik yamalarının tətbiq edilməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: MongoDB
FAQ2
Which MongoDB feature is affected by CVE-2026-18705?
This vulnerability affects the Atlas Vector Search feature of MongoDB Server.
What level of access does an attacker need to exploit CVE-2026-18705?
An attacker needs to be an authenticated user with read access to one view.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.