CVE-2026-82074
Awaiting Analysis Awaiting Analysis - Queue

Incorrect Authorization in MongoDB Server via Aggregation Framework

Vulnerability report for CVE-2026-82074, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: MongoDB, Inc.

Description

MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that causes the server's authorization subsystem to evaluate a different operation than what is actually executed, resulting in unauthorized read access to collection data within the target database.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mongodb mongodb_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MongoDB Server has an authorization flaw in its aggregation framework. An authenticated user with limited privileges can send a specially crafted aggregation request that tricks the authorization system into allowing access to data they should not be able to read.

Impact Analysis

If you use MongoDB Server, an attacker with minimal access could exploit this to read sensitive data from databases they are not authorized to access, potentially exposing confidential information.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating compliance requirements like GDPR or HIPAA which mandate strict data protection and access controls.

Mitigation Strategies

Update MongoDB Server to the latest patched version immediately to address the authorization flaw in the aggregation framework. Restrict user privileges to the minimum required for operations. Monitor database access logs for unusual aggregation queries or unauthorized data access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82074. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart