云虫漏洞库

CVE-2026-18696 - An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation. - 漏洞详情

漏洞编号:CVE-2026-18696

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-18696

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-863

发布/更新时间:2026-08-11 / 2026-08-28

漏洞描述

An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.

相关链接

相关漏洞

« 返回首页