AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18700

MEDIUM · CVSS 6.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

MongoDB Server is vulnerable due to a flaw in its geospatial validation that allows an authenticated user with write privileges to exploit concurrent operations, potentially leading to the use of freed memory. This vulnerability can result in a server crash, causing a denial of service. Organizations using MongoDB should prioritize patching this issue to maintain service availability and prevent potential disruptions.

CVE
CVE-2026-18700
Severity
MEDIUM
CVSS
6.5
EPSS
0.29%
MongoDB

Original NVD Description

An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed, through concurrent operations against a collection using a certain type of validator. This could result in a server crash, leading to a denial of service.