AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18699

MEDIUM · CVSS 6.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

MongoDB Server is vulnerable to a denial of service attack due to a flaw in its query planner, which can be exploited by authenticated users with read-level privileges through specially crafted queries targeting collections with text indexes. This vulnerability may lead to unexpected server terminations, disrupting service for connected clients and ongoing operations. Organizations using MongoDB should prioritize addressing this issue to maintain service availability and prevent potential disruptions.

CVE
CVE-2026-18699
Severity
MEDIUM
CVSS
6.5
EPSS
0.29%
MongoDB

Original NVD Description

An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index. This could result in a denial of service, affecting connected clients and in-flight operations.