CVE-2026-18705
EUVD-2026-5690811.08.2026, 19:17
An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mongodb | mongodb | 8.3.0 ≤ 𝑥 < 8.3.8 | CNA |
| mongodb | mongodb | 8.0 ≤ 𝑥 < 8.0.29 | CNA |
| mongodb | mongodb | 7.0 ≤ 𝑥 < 7.0.40 | CNA |