Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 08 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 06 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb mongodb
|
|
| CPEs | cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:* | |
| Vendors & Products |
Mongodb mongodb
|
Wed, 29 Apr 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb mongodb Server |
|
| Vendors & Products |
Mongodb
Mongodb mongodb Server |
Wed, 29 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. This could affect how authentication is performed for the impacted account. | |
| Title | Flaw in the updateUser Command May Allow Unauthorized Configuration Change | |
| Weaknesses | CWE-1284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-04-29T17:49:18.851Z
Reserved: 2026-04-23T14:59:47.210Z
Link: CVE-2026-6915
Updated: 2026-04-29T17:49:15.396Z
Status : Analyzed
Published: 2026-04-29T17:16:41.397
Modified: 2026-05-06T20:08:44.997
Link: CVE-2026-6915
OpenCVE Enrichment
Updated: 2026-05-08T14:00:10Z