AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18706

MEDIUM · CVSS 6.6 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

MongoDB Server is vulnerable due to an issue in the $graphLookup aggregation stage, which can lead to the use of freed memory by an authenticated user capable of executing aggregation and memory-management commands. This vulnerability may result in server crashes or the execution of unintended code, posing a risk to system stability and security. Organizations using MongoDB should prioritize this issue to mitigate potential disruptions and safeguard their applications.

CVE
CVE-2026-18706
Severity
MEDIUM
CVSS
6.6
EPSS
0.34%
MongoDB

Original NVD Description

An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or, potentially, execution of unintended code.