CVE-2026-82074

⚪ Do wiadomości

Błąd autoryzacji w MongoDB pozwala na nieautoryzowany dostęp do danych w bazie.

CVSS
6.5
EPSS
0.3%
Exploit
none
Vendor
mongodb
Opis źródłowy (NVD)

MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that causes the server's authorization subsystem to evaluate a different operation than what is actually executed, resulting in unauthorized read access to collection data within the target database.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-09-08 17:18:36 UTC
Ostatnia modyfikacja (NVD)2026-09-16 20:39:50 UTC
Referencje