CVE-2026-82074
Dashboard / Vulnerabilities / CVE-2026-82074
Summary: Incorrect Authorization in MongoDB Server Aggregation Framework Allows Unauthorized Read Access to Collection Data
Details: MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that causes the server's authorization subsystem to evaluate a different operation than what is actually executed, resulting in unauthorized read access to collection data within the target database.
References: https://jira.mongodb.org/browse/SERVER-132275, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82074.json, https://nvd.nist.gov/vuln/detail/CVE-2026-82074
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
