<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 03:40:45 +0000</lastBuildDate>
    <item>
      <title>BIT-mongodb-2026-18696 — Improper Authorization in MongoDB applyOps Command Handling Allows Unauthorized DDL Operations on Collections</title>
      <link>https://cve.radiocsirt.org/vuln/bit-mongodb-2026-18696</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: mongodb&lt;/p&gt;
&lt;p&gt;An issue in MongoDB Server&amp;#39;s applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: mongodb&lt;/p&gt;
&lt;p&gt;An issue in MongoDB Server&amp;#39;s applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-mongodb-2026-18696</guid>
    </item>
    <item>
      <title>EUVD-2026-351295</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351295</link>
      <description>EUVD-2026-351295</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351295</guid>
    </item>
    <item>
      <title>fkie_cve-2026-18696</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-18696</link>
      <description>&lt;p&gt;An issue in MongoDB Server&amp;#39;s applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue in MongoDB Server&amp;#39;s applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-18696</guid>
    </item>
    <item>
      <title>GHSA-85cq-4fh4-j8cv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-85cq-4fh4-j8cv</link>
      <description>&lt;p&gt;An issue in MongoDB Server&amp;#39;s applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue in MongoDB Server&amp;#39;s applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-85cq-4fh4-j8cv</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-18696</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-18696</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: mongodb, Ubuntu:Pro:16.04:LTS: mongodb, Ubuntu:Pro:18.04:LTS: mongodb, Ubuntu:Pro:20.04:LTS: mongodb&lt;/p&gt;
&lt;p&gt;An issue in MongoDB Server&amp;#39;s applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: mongodb, Ubuntu:Pro:16.04:LTS: mongodb, Ubuntu:Pro:18.04:LTS: mongodb, Ubuntu:Pro:20.04:LTS: mongodb&lt;/p&gt;
&lt;p&gt;An issue in MongoDB Server&amp;#39;s applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-18696</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2794 — MongoDB: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2794</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in MongoDB ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in MongoDB ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2794</guid>
    </item>
  </channel>
</rss>
