As of 3.2.11/3.4.0, mongorestore can use --oplogReplay with only the 'restore' role. A custom role with 'anyAction on anyResource' is not required. Reference:
At a minimum these pages are affected:
Other pages may have this issue as well – I didn't do an exhaustive search.