• Sources: primary, NVD API record, analysis, discussion
  • Summary: NVD carries CVE-2026-18690 from the cna@mongodb.com CNA, published 2026-08-11, at CVSS 3.1 8.1 and CVSS 4.0 7.2 under CWE-863, affecting 7.0 below 7.0.40, 8.0 below 8.0.29, and 8.3.0 below 8.3.8. The NVD HTML detail page timed out twice for this digest, so the record was read through the NVD 2.0 REST API instead, and both URLs are cited. The CISA SSVC entry on that record scores exploitation as none and automatable as no. The mechanism, that a collection name sent as a BSON symbol rather than a string takes a different path through namespace parsing and permission matching, is the RECON author's source reading and reproduction against 8.0.28 with the fix confirmed on 8.0.29, not MongoDB's description, and RECON is a vendor blog that closes with a product pitch. The three sibling CVEs that post summarises were not verified for this digest and are not restated here.
  • Why it matters: The precondition is holding a database-scoped role rather than full admin, which is the ordinary configuration for an application account, so most authenticated deployments meet it, and there is no configuration workaround.
  • Follow-up: Whether the sibling CVEs carry the same precondition, and whether MongoDB publishes its own technical detail.

send feedback on this story