CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server
Bulletin ID: 2026-076-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/05/2026 13:00 PM PDT
Description:
Amazon DocumentDB MCP Server is an open-source Model Context Protocol (MCP) server that enables AI assistants to interact with Amazon DocumentDB databases. We identified CVE-2026-18954, an incorrect authorization issue where write-capable aggregation pipeline stages ($out, $merge) bypass the read-only mode enforcement logic, potentially allowing an authenticated MCP client to perform write operations on the connected database.
Impacted versions: < 1.0.12
Resolution:
This issue has been addressed in Amazon DocumentDB MCP Server version 1.0.12. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds:
Configure the MCP server with database credentials for a read-only user (a user without write privileges), which enforces read-only access at the database level regardless of MCP server mode settings.
References:
Please email aws-security@amazon.com with any security questions or concerns.