AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18697

HIGH · CVSS 7.5 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

MongoDB Server's aggregation framework is vulnerable to a denial-of-service attack, where an unauthenticated attacker can exploit a specially crafted aggregation command to terminate the mongos router process. This disruption can lead to significant service interruptions for client connections relying on the affected instance. Organizations using MongoDB should prioritize addressing this vulnerability to maintain service availability and protect against potential exploitation.

CVE
CVE-2026-18697
Severity
HIGH
CVSS
7.5
EPSS
0.32%
MongoDB

Original NVD Description

An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service, disrupting client connections routed through the affected mongos instance.