bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: MCP Server

show all
Thursday, August 6, 2026

Amazon DocumentDB MCP Server: Authorization Bypass in Aggregation Pipeline

Amazon DocumentDB MCP Server versions below 1.0.12 have a nasty authorization flaw (CVE-2026-18954). Write-capable aggregation stages like $out and $merge can bypass read-only enforcement, letting authenticated clients sneak write operations past security controls. If you're running this open-source tool, upgrade immediately—this one requires your attention.

> source: aws.amazon.com