AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18687

HIGH · CVSS 7.1 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

MongoDB Server is vulnerable due to improper validation of request parameters during Queryable Encryption maintenance operations, which can be exploited by authenticated users with readWrite privileges. This flaw may lead to server crashes or excessive internal writes, causing resource exhaustion and potential corruption of encrypted index data. Organizations using MongoDB should prioritize addressing this vulnerability to protect their data integrity and maintain service availability.

CVE
CVE-2026-18687
Severity
HIGH
CVSS
7.1
EPSS
0.17%
MongoDB

Original NVD Description

MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypted index data.