Amazon DocumentDB MCP Server: Authorization Bypass in Aggregation Pipeline
Amazon DocumentDB MCP Server versions below 1.0.12 have a nasty authorization flaw (CVE-2026-18954). Write-capable aggregation stages like $out and $merge can bypass read-only enforcement, letting authenticated clients sneak write operations past security controls. If you're running this open-source tool, upgrade immediately—this one requires your attention.