AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18703

MEDIUM · CVSS 4.2 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

MongoDB Server is vulnerable to a flaw that permits users with valid client certificates to bypass configured authentication restrictions, potentially undermining the administrator's intent to limit authentication methods. This could lead to unauthorized access if an attacker exploits this weakness. Organizations using MongoDB should prioritize addressing this vulnerability to ensure their authentication mechanisms remain secure and effective.

CVE
CVE-2026-18703
Severity
MEDIUM
CVSS
4.2
EPSS
0.11%
MongoDB

Original NVD Description

An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to restrict authentication to other mechanisms. This could allow authentication through a method the administrator intended to disable.