CVE-2026-18954: Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate wri
Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic.
To remediate this issue, users should upgrade to version 1.0.12 or later.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-18954
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-189540.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18954 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Incorrect authorization in
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-65551: Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configu…nvd · 2026-08-06
- unknownCVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Se…aws · 2026-08-05
- highCVE-2025-63822: SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticat…nvd · 2026-08-05
- criticalCVE-2026-48333: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that coul…nvd · 2026-08-03
- mediumCVE-2026-28147: Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Fr…nvd · 2026-08-03
- highCVE-2026-18394: Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might al…nvd · 2026-07-31
More from NVD Recent CVEs
- highCVE-2026-19190: A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part …2026-08-07
- unknownCVE-2026-49746: Software installed and run as a non-privileged user may conduct improper GPU system calls to c…2026-08-07
- unknownCVE-2026-45204: Software installed and run as a non-privileged user may conduct improper GPU system calls to t…2026-08-07
- unknownCVE-2026-45198: Kernel software from a non-secure operating system on a platform with Trusted Execution Enviro…2026-08-07
- highCVE-2026-19189: A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue …2026-08-07