THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18712 (HIGH 8.1) — An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different collection. This is due to insufficient valida

[NVD] CVE-2026-18712 (HIGH 8.1) — An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different collection. This is due to insufficient valida

mednvdPublished 2026-08-11

CVE-2026-18712 CVSS: 8.1 HIGH Published: 2026-08-11T19:17:29.360

An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different collection. This is due to insufficient validation of certain internal metadata references before th

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18712