---
id: CVE-2026-18698
title: >-
  An issue in MongoDB Server could allow an authenticated user with a limited
  database-scoped role to perform an action against protected system collections
  that should require more specific privileges
summary: >-
  An issue in MongoDB Server could allow an authenticated user with a limited
  database-scoped role to perform an action against protected system collections
  that should require more specific privileges. This could result in exposure of
  col…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-863
vendor: mongodb
product: mongodb
affected:
  - 'mongodb >= 7.0.0, < 7.0.40'
  - 'mongodb >= 8.0.0, < 8.0.29'
  - 'mongodb >= 8.2.0, <= 8.2.12'
  - 'mongodb >= 8.3.0, < 8.3.8'
  - mongodb = 9.0.0
  - mongodb = 9.1.0
patched:
  - mongodb 8.3.8
published: '2026-08-11'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T15:17:51.067'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18698'
references:
  - url: 'https://jira.mongodb.org/browse/SERVER-130481'
    label: cna@mongodb.com
tags:
  - nvd
epss: 0.00172
epssPercentile: 0.06907
ingestedAt: '2026-08-29T19:41:15.801Z'
---

## Overview

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metadata and, on certain deployment configurations, unauthorized modification of system collection data.

## Affected

- `mongodb >= 7.0.0, < 7.0.40`
- `mongodb >= 8.0.0, < 8.0.29`
- `mongodb >= 8.2.0, <= 8.2.12`
- `mongodb >= 8.3.0, < 8.3.8`
- `mongodb = 9.0.0`
- `mongodb = 9.1.0`

## Remediation

Upgrade past the affected range:

- `mongodb 8.3.8`
