MEDIUMVulnerability

CVE-2026-82074

MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that causes the server's authorization subsystem to evaluate a different operation than what is actually executed, resulting in unauthorized read access to collection data within the target database.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-82074
signal_observed_at
2026-09-16T21:37:08+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-09-08T17:18:36.403
last_modified
2026-09-16T20:39:50.690

Related Entities (3)

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82074 — Ninja Signal Threat Intelligence | Ninja Signal