To remediate this issue, users should upgrade to version 1.0.12 or later.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 05 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic. To remediate this issue, users should upgrade to version 1.0.12 or later. | |
| Title | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server | |
| First Time appeared |
Aws
Aws documentdb-mcp-server |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:aws:documentdb-mcp-server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws documentdb-mcp-server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-08-05T20:07:35.451Z
Reserved: 2026-08-05T13:45:00.654Z
Link: CVE-2026-18954
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-863
Incorrect Authorization