Description
Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic.



To remediate this issue, users should upgrade to version 1.0.12 or later.
Published: 2026-08-05
Score: 5.7 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an authenticated MCP client to perform inappropriate write operations on the connected database through write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic. This can lead to data tampering, loss of integrity, and potential disruption of services. The weakness is categorized as CWE‑863, indicating a failure to correctly enforce authorization checks.

Affected Systems

AWS DocumentDB MCP Server, versions prior to 1.0.12. The affected product is the MCP Server component from AWS Labs, as reflected by the vendor product listing.

Risk and Exploitability

The CVSS score of 5.7 classifies the issue as moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation activity. However, the attack requires an authenticated MCP client with network access to the MCP Server. Once authenticated, the client can craft aggregation pipelines that exploit the authorization bypass, allowing writes that should be prohibited.

Generated by OpenCVE AI on August 5, 2026 at 21:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade AWS DocumentDB MCP Server to version 1.0.12 or later
  • Ensure all MCP clients are updated to the latest patched version
  • Configure IAM policies to restrict MCP client permissions to the minimum necessary, and enforce read-only mode where applicable

Generated by OpenCVE AI on August 5, 2026 at 21:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic. To remediate this issue, users should upgrade to version 1.0.12 or later.
Title Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server
First Time appeared Aws
Aws documentdb-mcp-server
Weaknesses CWE-863
CPEs cpe:2.3:a:aws:documentdb-mcp-server:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws documentdb-mcp-server
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Aws Documentdb-mcp-server
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-08-05T20:07:35.451Z

Reserved: 2026-08-05T13:45:00.654Z

Link: CVE-2026-18954

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T21:45:04Z

Weaknesses