CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server
Cybersecurity Classified by Officially
CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server
Bulletin ID: 2026-076-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/05/2026 13:00 PM PDT
Amazon DocumentDB MCP Server is an open-source Model Context Protocol (MCP) server that enables AI assistants to interact with Amazon DocumentDB databases. We identified CVE-2026-18954, an incorrect authorization issue where write-capable aggregation pipeline stages ($out, $merge) bypass the read-only mode enforcement logic, potentially allowing an authenticated MCP client to perform write operations on the connected database.
This issue has been addressed in Amazon DocumentDB MCP Server version 1.0.12. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Configure the MCP server with database credentials for a read-only user (a user without write privileges), which enforces read-only access at the database level regardless of MCP server mode settings.
This is an extract. The publication continues at the source.
Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-076-aws/
Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Amazon Web Services — imported from official source
- Official source
- https://aws.amazon.com/security/security-bulletins/feed/ RSS
- Imported
- September 18, 2026 09:42
- Versions
- 1 recorded
- Identity
-
6607269944d43dc0f46ffcbd4457e7c4bca06771