CVE-2026-6915
MEDIUMFlaw in the updateUser Command May Allow Unauthorized Configuration Change
Title source: cnaDescription
An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. This could affect how authentication is performed for the impacted account.
References (1)
Scores
CVSS v3
6.3
EPSS
0.0006
EPSS Percentile
19.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1284
Status
published
Products (3)
MongoDB/MongoDB Server
7.0.0 - 7.0.32
MongoDB/MongoDB Server
8.0.0 - 8.0.21
MongoDB/MongoDB Server
8.2.0 - 8.2.7
Published
Apr 29, 2026
Tracked Since
Apr 29, 2026