Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/SERVER-129618 |
|
Tue, 11 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process. | |
| Title | Improper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Access to Protected View Data | |
| Weaknesses | CWE-807 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-08-11T20:25:24.950Z
Reserved: 2026-08-03T15:53:44.960Z
Link: CVE-2026-18705
Updated: 2026-08-11T20:25:21.245Z
Status : Received
Published: 2026-08-11T19:17:25.207
Modified: 2026-08-11T21:17:33.343
Link: CVE-2026-18705
No data.
OpenCVE Enrichment
No data.