CVE-2026-6915
Received
Received - Intake
Authentication Bypass in User Management Command
Publication date: 2026-04-29
Last updated on: 2026-05-06
Assigner: MongoDB, Inc.
Description
Description
An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. This could affect how authentication is performed for the impacted account.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mongodb | mongodb | From 7.0.0 (inc) to 7.0.32 (exc) |
| mongodb | mongodb | From 8.0.0 (inc) to 8.0.21 (exc) |
| mongodb | mongodb | From 8.2.0 (inc) to 8.2.7 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1284 | The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties. |