To remediate this issue, users should upgrade to version 1.0.12 or later.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 06 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 05 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic. To remediate this issue, users should upgrade to version 1.0.12 or later. | |
| Title | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server | |
| First Time appeared |
Aws
Aws documentdb-mcp-server |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:aws:documentdb-mcp-server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws documentdb-mcp-server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-08-06T13:33:02.167Z
Reserved: 2026-08-05T13:45:00.654Z
Link: CVE-2026-18954
Updated: 2026-08-06T13:11:49.469Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T21:45:04Z