Vulnerability Bulletins

CVE-2026-18705

   
Affected software MONGODB
 
An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-18705