<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T03:40:57.180694+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-mongodb-2026-18696</id>
    <title>BIT-mongodb-2026-18696 — Improper Authorization in MongoDB applyOps Command Handling Allows Unauthorized DDL Operations on Collections</title>
    <updated>2026-10-04T03:40:57.184359+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: mongodb</p>
<p>An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-mongodb-2026-18696"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-351295</id>
    <title>EUVD-2026-351295</title>
    <updated>2026-10-04T03:40:57.184406+00:00</updated>
    <content>EUVD-2026-351295</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-351295"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-18696</id>
    <title>fkie_cve-2026-18696</title>
    <updated>2026-10-04T03:40:57.184422+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-18696"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-85cq-4fh4-j8cv</id>
    <title>GHSA-85cq-4fh4-j8cv</title>
    <updated>2026-10-04T03:40:57.184445+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-85cq-4fh4-j8cv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-18696</id>
    <title>UBUNTU-CVE-2026-18696</title>
    <updated>2026-10-04T03:40:57.184461+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: mongodb, Ubuntu:Pro:16.04:LTS: mongodb, Ubuntu:Pro:18.04:LTS: mongodb, Ubuntu:Pro:20.04:LTS: mongodb</p>
<p>An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-18696"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2794</id>
    <title>WID-SEC-W-2026-2794 — MongoDB: Mehrere Schwachstellen</title>
    <updated>2026-10-04T03:40:57.184485+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in MongoDB ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2794"/>
  </entry>
</feed>
