MongoDB Server vulnerability

An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process.

Published 11 Aug 2026Updated 16 Sep 20261 sources
CVSS 7.1

Source timeline

CVE record published by NVDView source ↗