MEDIUMVulnerability
CVE-2026-82074
MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that causes the server's authorization subsystem to evaluate a different operation than what is actually executed, resulting in unauthorized read access to collection data within the target database.
Properties
- severity
- MEDIUM
- score
- 6.5
- cve_id
- CVE-2026-82074
- signal_observed_at
- 2026-09-16T21:37:08+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- published_at
- 2026-09-08T17:18:36.403
- last_modified
- 2026-09-16T20:39:50.690
Related Entities (3)
AFFECTS_PRODUCT (1)
→[Product]
HAS_WEAKNESS (1)
→[Weakness]Incorrect Authorization
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph