What is CVE-2026-18954?
This vulnerability in Amazon AWS Labs DocumentDB MCP Server before version 1.0.12 allows an authenticated MCP client to bypass the read-only mode and perform write operations on the database via the aggregation pipeline tool. Users should immediately upgrade to version 1.0.12 or later.
Azərbaycanca: Amazon AWS Labs DocumentDB MCP Server-in 1.0.12-dən əvvəlki versiyalarında mövcud olan bu boşluq, autentifikasiya olunmuş MCP müştərisinə "aggregation pipeline" aləti vasitəsilə yalnız oxuma rejimindən yan keçərək verilənlər bazasında yazma əməliyyatları icra etməyə imkan verir. İstifadəçilərə dərhal 1.0.12 və ya daha yuxarı versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of Amazon AWS Labs DocumentDB MCP Server are affected by CVE-2026-18954?
Versions before 1.0.12 are affected.
What can an authenticated MCP client do by exploiting CVE-2026-18954?
Bypass the read-only mode and perform write operations on the database via the aggregation pipeline tool.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.