CVE-2026-18702
Awaiting Analysis Awaiting Analysis - Queue

Diagnostic Logging Bypass in MongoDB Server

Vulnerability report for CVE-2026-18702, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-28

Assigner: MongoDB, Inc.

Description

An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the intended database. This could allow suppression of diagnostic logging server-wide, potentially obscuring unauthorized activity, or degrade operational monitoring by causing excessive log volume.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-28
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mongodb mongodb_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in MongoDB Server allows an authenticated user with limited database privileges to modify diagnostic logging settings for the entire server instead of just their database. This could let them suppress server-wide logs, hiding unauthorized activity, or overload the system with excessive logs, degrading monitoring capabilities.

Detection Guidance

This vulnerability involves diagnostic logging settings being modified by an authenticated user with limited privileges. To detect it, monitor MongoDB server logs for unexpected changes in logging configuration or unusual suppression of diagnostic logs. Check for modifications to the logLevel or diagnosticLogVerbosity settings in the MongoDB configuration files or via the admin command interface.

Impact Analysis

If exploited, this vulnerability could allow attackers to hide their actions by disabling logs or overwhelm the system with logs, making it harder to detect breaches. It may also lead to operational disruptions due to excessive logging.

Compliance Impact

This vulnerability could impact compliance by preventing proper logging of user activities, which is required for audits and breach detection under standards like GDPR and HIPAA. Suppressed logs may lead to non-compliance and legal penalties.

Mitigation Strategies

Immediately update MongoDB Server to the latest patched version to address the issue with diagnostic logging settings. Review and restrict database-scoped privileges to prevent unauthorized modifications to server-wide logging configurations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18702. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart