All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-18702
MEDIUMpublished 2026-08-11 19:17 UTC · 1 day ago · modified 2026-08-11 21:17 UTC
5.3
CVSS / 10
// description
An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the intended database. This could allow suppression of diagnostic logging server-wide, potentially obscuring unauthorized activity, or degrade operational monitoring by causing excessive log volume.
// weaknesses (CWE)
- CWE-269