
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-18712 is an Incorrect Authorization vulnerability in MongoDB Server's Queryable Encryption feature that allows an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different collection. The flaw stems from insufficient validation of certain internal metadata references before they are used to perform operations on other namespaces. Affected versions include MongoDB Server 7.0.x before 7.0.40, 8.0.x before 8.0.29, and 8.3.x before 8.3.8. It was published on August 11, 2026, with a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 7.2 (High) (GitHub Advisory, MongoDB Jira).
The vulnerability is classified as CWE-863 (Incorrect Authorization), arising from MongoDB Server's Queryable Encryption maintenance operations failing to adequately validate internal metadata references before applying them to operations across different database namespaces. An authenticated attacker with low-level privileges on one encrypted collection can craft or manipulate maintenance operation requests such that the server incorrectly resolves metadata references to a different, unintended encrypted collection. No special configuration or user interaction is required beyond holding valid credentials with privileges on at least one encrypted collection (GitHub Advisory, MongoDB Jira).
Successful exploitation allows an authenticated attacker to cause unauthorized modification or destruction of data in encrypted collections they do not have explicit privileges over, resulting in high integrity and availability impact with no confidentiality exposure. This cross-collection data tampering could corrupt or permanently destroy sensitive encrypted data managed by other database users or applications, potentially causing significant data loss or service disruption. The scope is limited to the vulnerable MongoDB Server instance, with no evidence of subsequent system impact (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.175% (7th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires authenticated access with at least low-level privileges on an encrypted collection, and the attack is not automatable according to NVD SSVC assessment.
compactStructuredEncryptionData) targeting collections that the executing user does not have explicit privileges on.MongoDB has released patched versions addressing this vulnerability: 7.0.40, 8.0.29, and 8.3.8. Users should upgrade to the appropriate fixed version as the primary remediation (GitHub Advisory, MongoDB Jira). As a workaround until patching is possible, restrict Queryable Encryption privileges strictly to only the collections that require them and enforce the principle of least privilege for all database user permissions. Additionally, monitor audit logs for unauthorized data modifications or deletions across collections to detect potential exploitation attempts.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."