Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/SERVER-132275 |
|
Tue, 08 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that causes the server's authorization subsystem to evaluate a different operation than what is actually executed, resulting in unauthorized read access to collection data within the target database. | |
| Title | Incorrect Authorization in MongoDB Server Aggregation Framework Allows Unauthorized Read Access to Collection Data | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-08T17:51:37.697Z
Reserved: 2026-08-27T22:53:55.358Z
Link: CVE-2026-82074
No data.
Status : Received
Published: 2026-09-08T17:18:36.403
Modified: 2026-09-08T17:18:36.403
Link: CVE-2026-82074
No data.
OpenCVE Enrichment
No data.
-
CWE-863
Incorrect Authorization