AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18688

HIGH · CVSS 7.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

MongoDB Server's aggregation framework is vulnerable to an out-of-bounds memory read caused by specially crafted numeric parameters in aggregation pipeline stages, which can lead to server crashes and potential exposure of sensitive memory contents. Organizations using MongoDB should prioritize patching this vulnerability to mitigate the risk of denial-of-service attacks and data leakage.

CVE
CVE-2026-18688
Severity
HIGH
CVSS
7.1
EPSS
0.27%
MongoDB

Original NVD Description

An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage. This could result in a server crash (denial of service) and may potentially expose a limited amount of memory contents.