CVE-2026-18705
Awaiting Analysis Awaiting Analysis - Queue

Atlas Vector Search Information Disclosure in MongoDB Server

Vulnerability report for CVE-2026-18705, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-28

Assigner: MongoDB, Inc.

Description

An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-28
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mongodb mongodb_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-807 The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in MongoDB Server's Atlas Vector Search allows an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. It occurs due to insufficient handling of user-supplied fields when constructing an internal request forwarded to the search process.

Detection Guidance

This vulnerability involves unauthorized access to protected views in MongoDB Atlas Vector Search. Detection requires reviewing MongoDB server logs for unusual queries accessing unrelated views, checking for anomalous read patterns, and validating access controls. No specific commands are provided in the context.

Impact Analysis

An attacker could access sensitive data from protected views, leading to unauthorized information disclosure. This could result in data breaches, loss of confidentiality, or compliance violations depending on the exposed data.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles or HIPAA's confidentiality requirements. Organizations may face fines or penalties for non-compliance if data breaches occur due to this issue.

Mitigation Strategies

Update MongoDB Server to the latest patched version to address the Atlas Vector Search issue. Ensure proper access controls are enforced to prevent unauthorized access between views.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18705. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart