Impact
The vulnerability allows an authenticated MCP client to perform inappropriate write operations on the connected database through write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic. This can lead to data tampering, loss of integrity, and potential disruption of services. The weakness is categorized as CWE‑863, indicating a failure to correctly enforce authorization checks.
Affected Systems
AWS DocumentDB MCP Server, versions prior to 1.0.12. The affected product is the MCP Server component from AWS Labs, as reflected by the vendor product listing.
Risk and Exploitability
The CVSS score of 5.7 classifies the issue as moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation activity. However, the attack requires an authenticated MCP client with network access to the MCP Server. Once authenticated, the client can craft aggregation pipelines that exploit the authorization bypass, allowing writes that should be prohibited.
OpenCVE Enrichment