Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic.
To remediate this issue, users should upgrade to version 1.0.12 or later.
References
| Link | Resource |
|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-076-aws/ | Vendor Advisory |
| https://github.com/awslabs/mcp/releases/tag/2026.04.20260408085348 | Release Notes |
| https://github.com/awslabs/mcp/security/advisories/GHSA-j694-4m5j-w8hc | Vendor Advisory |
Configurations
History
10 Aug 2026, 15:23
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://aws.amazon.com/security/security-bulletins/2026-076-aws/ - Vendor Advisory | |
| References | () https://github.com/awslabs/mcp/releases/tag/2026.04.20260408085348 - Release Notes | |
| References | () https://github.com/awslabs/mcp/security/advisories/GHSA-j694-4m5j-w8hc - Vendor Advisory | |
| First Time |
Amazon
Amazon documentdb Mcp Server |
|
| CPE | cpe:2.3:a:amazon:documentdb_mcp_server:*:*:*:*:*:python:*:* |
06 Aug 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
05 Aug 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-08-05 20:17
Updated : 2026-08-10 15:23
NVD link : CVE-2026-18954
Mitre link : CVE-2026-18954
CVE.ORG link : CVE-2026-18954
JSON object : View
Products Affected
amazon
- documentdb_mcp_server
CWE
CWE-863
Incorrect Authorization
