CVE-2026-18954

Source
https://cve.org/CVERecord?id=CVE-2026-18954
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18954.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-18954
Aliases
  • GHSA-j694-4m5j-w8hc
Published
2026-08-05T20:07:35.451Z
Modified
2026-08-08T03:30:48.687757903Z
Severity
  • 5.7 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server
Details

Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic.

To remediate this issue, users should upgrade to version 1.0.12 or later.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18954.json",
    "cna_assigner": "AMZN",
    "cwe_ids": [
        "CWE-863"
    ],
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "1.0.12"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "extracted_events": [
                {
                    "fixed": "1.0.12"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "fixed": "1.0.12"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/awslabs/mcp

Affected ranges

Type
GIT
Repo
https://github.com/awslabs/mcp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

0.*
0.0.0
2025.*
2025.07.20250724233019
2025.07.20250725184343
2025.07.20250725211158
2025.07.20250729091616
2025.07.20250731231632
2025.08.20250804210840
2025.08.20250806001353
2025.08.20250807085838
2025.08.20250808023730
2025.08.20250811131021
2025.08.20250812201949
2025.08.20250813183540
2025.08.20250819174331
2025.08.20250821164033
2025.08.20250822191015
2025.08.20250825171959
2025.08.20250827205925
2025.08.20250829143415
2025.09.20250904164828
2025.09.20250909205525
2025.09.20250915155108
2025.09.20250922121130
2025.09.20250922202404
2025.09.20250923142420
2025.09.20250924194012
2025.09.20250929221000
2025.09.20250930154414
2025.09.20250930190615
2025.10.20251001171005
2025.10.20251002031219
2025.10.20251006150229
2025.10.20251013201003
2025.10.20251022170206
2025.10.20251024213946
2025.10.20251027191808
2025.10.20251028223010
2025.10.20251029214701
2025.10.20251030150555
2025.10.20251030153754
2025.10.20251031142413
2025.10.20251031202646
2025.11.20251103095936
2025.11.20251107160628
2025.11.20251107230454
2025.11.20251113105935
2025.11.20251114173808
2025.11.20251119132423
2025.11.20251120134931
2025.11.20251120162446
2025.11.20251120192945
2025.11.20251121001139
2025.11.20251121220339
2025.11.20251122013630
2025.11.20251124194829
2025.11.20251124232317
2025.11.20251126165607
2025.11.20251128160211
2025.12.20251202213310
2025.12.20251208100753
2025.12.20251210024918
2025.12.20251211225414
2025.12.20251219001245
2025.12.20251223100855
2025.12.20251230231100
2025.3.311549
2025.3.311709
2025.3.311803
2025.4.010022
2025.4.010233
2025.4.010417
2025.4.010652
2025.4.011704
2025.4.031003
2025.4.031155
2025.4.031959
2025.4.061003
2025.4.071717
2025.4.081004
2025.4.081650
2025.4.091004
2025.4.101004
2025.4.111003
2025.4.111440
2025.4.2025112152
2025.4.2025141004
2025.4.2025151004
2025.4.2025151848
2025.4.2025152002
2025.4.2025171004
2025.4.2025211854
2025.4.2025222218
2025.4.2025241004
2025.4.2025281037
2025.5.2025011004
2025.5.2025021004
2025.5.2025031003
2025.5.2025061004
2025.5.2025081004
2025.5.2025090157
2025.5.2025090231
2025.5.2025101003
2025.5.2025131004
2025.5.2025132058
2025.5.2025132142
2025.5.2025132319
2025.5.2025132337
2025.5.2025150005
2025.5.2025151004
2025.5.2025151932
2025.5.2025160041
2025.5.2025161004
2025.5.2025161630
2025.5.2025171003
2025.5.2025211004
2025.5.2025211545
2025.5.2025211620
2025.5.2025211841
2025.5.2025212143
2025.5.2025222004
2025.5.2025231004
2025.5.2025241003
2025.5.2025261007
2025.5.2025271004
2025.5.2025271625
2025.5.2025281004
2025.5.2025282229
2025.5.2025290001
2025.5.2025290053
2025.5.2025291004
2025.5.2025291624
2025.5.2025291822
2025.5.2025292200
2025.5.2025292250
2025.5.2025292326
2025.5.2025300349
2025.6.2025031705
2025.6.2025042327
2025.6.2025052005
2025.6.2025061705
2025.6.2025102116
2025.6.2025111704
2025.6.2025111941
2025.6.2025112328
2025.6.2025131609
2025.6.2025131704
2025.6.2025171901
2025.6.2025191704
2025.6.2025201704
2025.6.2025220251
2025.6.2025272112
2025.7.2025012157
2025.7.2025031705
2025.7.2025032025
2025.7.2025040158
2025.7.2025072334
2025.7.2025092020
2025.7.2025092044
2025.7.2025102317
2025.7.2025111847
2025.7.2025112204
2025.7.2025141706
2025.7.2025142146
2025.7.2025151743
2025.7.2025152206
2025.7.2025180013
2025.7.2025181816
2025.7.2025211706
2025.7.2025232235
2026.*
2026.01.20260105153228
2026.01.20260109012952
2026.01.20260115004242
2026.01.20260121110136
2026.01.20260123211230
2026.01.20260126220610
2026.02.20260204163019
2026.02.20260205164349
2026.02.20260212091017
2026.02.20260213033417
2026.02.20260213185627
2026.02.20260217093030
2026.02.20260219104155
2026.02.20260223082610
2026.02.20260224162646
2026.02.20260224185711
2026.03.20260304183356
2026.03.20260305133104
2026.03.20260306090751
2026.03.20260309170740
2026.03.20260309214930
2026.03.20260313194041
2026.03.20260317204736
2026.03.20260324183211
2026.03.20260325200733
2026.03.20260327170559
2026.03.20260331185831
2026.04.20260402081408

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18954.json"