5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Description
An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. This could affect how authentication is performed for the impacted account.
Basic Information
ID
CVE-2026-6915
Source
mongodb
Published
Apr 29, 2026 at 16:51
Affected Product
Vendor
MongoDB
Product
MongoDB Server
Version
8.2.0
Affected Versions
MongoDB MongoDB Server 8.2.0
MongoDB MongoDB Server 8.0.0
MongoDB MongoDB Server 7.0.0
MongoDB MongoDB Server 8.0.0
MongoDB MongoDB Server 7.0.0