Medium severity6.4NVD Advisory· Published Aug 11, 2026· Updated Sep 16, 2026
CVE-2026-18702
CVE-2026-18702
Description
An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the intended database. This could allow suppression of diagnostic logging server-wide, potentially obscuring unauthorized activity, or degrade operational monitoring by causing excessive log volume.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
1- jira.mongodb.org/browse/SERVER-130198nvdVendor AdvisoryIssue Tracking
News mentions
2- MongoDB: 25 Vulnerabilities Disclosed, Including Critical BI Connector FlawsVypr Intelligence · Aug 12, 2026
- MongoDB Server: Thirteen Vulnerabilities Disclosed in Single BatchVypr Intelligence · Aug 11, 2026