Medium severity5.4NVD Advisory· Published Aug 11, 2026· Updated Sep 16, 2026
CVE-2026-18698
CVE-2026-18698
Description
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metadata and, on certain deployment configurations, unauthorized modification of system collection data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
1- jira.mongodb.org/browse/SERVER-130481nvdVendor AdvisoryIssue Tracking
News mentions
2- MongoDB: 25 Vulnerabilities Disclosed, Including Critical BI Connector FlawsVypr Intelligence · Aug 12, 2026
- MongoDB Server: Thirteen Vulnerabilities Disclosed in Single BatchVypr Intelligence · Aug 11, 2026