Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic.
To remediate this issue, users should upgrade to version 1.0.12 or later.
To remediate this issue, users should upgrade to version 1.0.12 or later.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 05 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic. To remediate this issue, users should upgrade to version 1.0.12 or later. | |
| Title | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server | |
| First Time appeared |
Aws
Aws documentdb-mcp-server |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:aws:documentdb-mcp-server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws documentdb-mcp-server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-08-05T20:07:35.451Z
Reserved: 2026-08-05T13:45:00.654Z
Link: CVE-2026-18954
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses