CVE-2026-18702: Improper Authorization in MongoDB profile Command Allows Unauthorized Modification of Server-Wide Diagnostic Settings
An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the intended database. This could allow suppression of diagnostic logging server-wide, potentially obscuring unauthorized activity, or degrade operational monitoring by causing excessive log volume.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18702?
CVE-2026-18702 has a medium severity score of 6.4.
What does CVE-2026-18702 affect?
CVE-2026-18702 affects the MongoDB Server, allowing unauthorized modification of server-wide diagnostic settings.
How can I fix CVE-2026-18702?
To fix CVE-2026-18702, ensure that users with limited, database-scoped privileges do not have access to modify the server-wide logging settings.
What could happen if CVE-2026-18702 is exploited?
Exploitation of CVE-2026-18702 could allow an attacker to suppress diagnostic logging server-wide, obscuring potential issues.
Who is impacted by CVE-2026-18702?
CVE-2026-18702 impacts MongoDB users who have configured database-scoped privileges that may unintentionally allow unauthorized changes.