AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18694

HIGH · CVSS 7.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

MongoDB Server is vulnerable due to improper validation in its geospatial query processing, allowing authenticated users with write privileges to store malformed geometry data. This flaw can lead to server crashes (denial of service) and potentially expose sensitive memory contents. Organizations using MongoDB, particularly those with user write access, should prioritize addressing this vulnerability to mitigate risks associated with service disruption and data exposure.

CVE
CVE-2026-18694
Severity
HIGH
CVSS
7.1
EPSS
0.27%
MongoDB

Original NVD Description

An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed without proper validation. Subsequent queries against this data could then result in the server accessing memory outside its intended bounds. This could result in a server crash (denial of service) and may expose a limited amount of server process memory.