{"id":"CVE-2026-18954","summary":"Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server","details":"Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic.\n\n\n\nTo remediate this issue, users should upgrade to version 1.0.12 or later.","aliases":["GHSA-j694-4m5j-w8hc"],"modified":"2026-08-08T03:30:48.687757903Z","published":"2026-08-05T20:07:35.451Z","database_specific":{"cna_assigner":"AMZN","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18954.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"1.0.12"}]},{"source":"CPE_FIELD","extracted_events":[{"fixed":"1.0.12"}]},{"extracted_events":[{"fixed":"1.0.12"}],"source":"DESCRIPTION"}]},"references":[{"type":"ADVISORY","url":"https://aws.amazon.com/security/security-bulletins/2026-076-aws/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18954.json"},{"type":"ADVISORY","url":"https://github.com/awslabs/mcp/security/advisories/GHSA-j694-4m5j-w8hc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18954"},{"type":"FIX","url":"https://github.com/awslabs/mcp/releases/tag/2026.04.20260408085348"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/awslabs/mcp","events":[{"introduced":"0"},{"fixed":"f2081406e449ae7e9ade296922146ab051729a2b"}],"database_specific":{"source":"REFERENCES"}}],"versions":["2026.04.20260402081408","2026.03.20260331185831","2026.03.20260327170559","2026.03.20260325200733","2026.03.20260324183211","2026.03.20260317204736","2026.03.20260313194041","2026.03.20260309214930","2026.03.20260309170740","2026.03.20260306090751","2026.03.20260305133104","2026.03.20260304183356","2026.02.20260224185711","2026.02.20260224162646","2026.02.20260223082610","2026.02.20260219104155","2026.02.20260217093030","2026.02.20260213185627","2026.02.20260213033417","2026.02.20260212091017","2026.02.20260205164349","2026.02.20260204163019","2026.01.20260126220610","2026.01.20260123211230","2026.01.20260121110136","2026.01.20260115004242","2026.01.20260109012952","2026.01.20260105153228","2025.12.20251230231100","2025.12.20251223100855","2025.12.20251219001245","2025.12.20251211225414","2025.12.20251210024918","2025.12.20251208100753","2025.12.20251202213310","2025.11.20251128160211","2025.11.20251126165607","2025.11.20251124232317","2025.11.20251124194829","2025.11.20251122013630","2025.11.20251121220339","2025.11.20251121001139","2025.11.20251120192945","2025.11.20251120162446","2025.11.20251120134931","2025.11.20251119132423","2025.11.20251114173808","2025.11.20251113105935","2025.11.20251107230454","2025.11.20251107160628","2025.11.20251103095936","2025.10.20251031202646","2025.10.20251031142413","2025.10.20251030153754","2025.10.20251030150555","2025.10.20251029214701","2025.10.20251028223010","2025.10.20251027191808","2025.10.20251024213946","2025.10.20251022170206","2025.10.20251013201003","2025.10.20251006150229","2025.10.20251002031219","2025.10.20251001171005","2025.09.20250930190615","2025.09.20250930154414","2025.09.20250929221000","2025.09.20250924194012","2025.09.20250923142420","2025.09.20250922202404","2025.09.20250922121130","2025.09.20250915155108","2025.09.20250909205525","2025.09.20250904164828","2025.08.20250829143415","2025.08.20250827205925","2025.08.20250825171959","2025.08.20250822191015","2025.08.20250821164033","2025.08.20250819174331","2025.08.20250813183540","2025.08.20250812201949","2025.08.20250811131021","2025.08.20250808023730","2025.08.20250807085838","2025.08.20250806001353","2025.08.20250804210840","2025.07.20250731231632","2025.07.20250729091616","2025.07.20250725211158","2025.07.20250725184343","2025.07.20250724233019","2025.7.2025232235","2025.7.2025211706","2025.7.2025181816","2025.7.2025180013","2025.7.2025152206","2025.7.2025151743","2025.7.2025142146","2025.7.2025141706","2025.7.2025112204","2025.7.2025111847","2025.7.2025102317","2025.7.2025092044","2025.7.2025092020","2025.7.2025072334","2025.7.2025040158","2025.7.2025032025","2025.7.2025031705","2025.7.2025012157","2025.6.2025272112","2025.6.2025220251","2025.6.2025201704","2025.6.2025191704","2025.6.2025171901","2025.6.2025131704","2025.6.2025131609","2025.6.2025112328","2025.6.2025111941","2025.6.2025111704","2025.6.2025102116","2025.6.2025061705","2025.6.2025052005","2025.6.2025042327","2025.6.2025031705","2025.5.2025300349","2025.5.2025292326","2025.5.2025292250","2025.5.2025292200","2025.5.2025291822","2025.5.2025291624","2025.5.2025291004","2025.5.2025290053","2025.5.2025290001","2025.5.2025282229","2025.5.2025281004","2025.5.2025271625","2025.5.2025271004","2025.5.2025261007","2025.5.2025241003","2025.5.2025231004","2025.5.2025222004","2025.5.2025212143","2025.5.2025211841","2025.5.2025211620","2025.5.2025211545","2025.5.2025211004","2025.5.2025171003","2025.5.2025161630","2025.5.2025161004","2025.5.2025160041","2025.5.2025151932","2025.5.2025151004","2025.5.2025150005","2025.5.2025132337","2025.5.2025132319","2025.5.2025132142","2025.5.2025132058","2025.5.2025131004","2025.5.2025101003","2025.5.2025090231","2025.5.2025090157","2025.5.2025081004","2025.5.2025061004","2025.5.2025031003","2025.5.2025021004","2025.5.2025011004","2025.4.2025281037","2025.4.2025241004","2025.4.2025222218","2025.4.2025211854","2025.4.2025171004","2025.4.2025152002","2025.4.2025151848","2025.4.2025151004","2025.4.2025141004","2025.4.2025112152","2025.4.111440","2025.4.111003","2025.4.101004","2025.4.091004","2025.4.081650","2025.4.081004","2025.4.071717","2025.4.061003","2025.4.031959","2025.4.031155","2025.4.031003","2025.4.011704","2025.4.010652","2025.4.010417","2025.4.010233","2025.4.010022","2025.3.311803","2025.3.311709","2025.3.311549","0.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18954.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}