Medium severity6.5NVD Advisory· Published Aug 11, 2026· Updated Sep 16, 2026
CVE-2026-18705
CVE-2026-18705
Description
An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
1- jira.mongodb.org/browse/SERVER-129618nvdVendor AdvisoryIssue Tracking
News mentions
1- MongoDB: 25 Vulnerabilities Disclosed, Including Critical BI Connector FlawsVypr Intelligence · Aug 12, 2026