AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18707

MEDIUM · CVSS 4.3 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

MongoDB Server is vulnerable to a denial-of-service attack, where an authenticated user, even without specific privileges, can crash the server by sending a specially crafted aggregation command. Organizations using MongoDB should prioritize patching this vulnerability to prevent potential service disruptions. This issue is particularly relevant for environments where user access is not tightly controlled.

CVE
CVE-2026-18707
Severity
MEDIUM
CVSS
4.3
EPSS
0.26%
MongoDB

Original NVD Description

An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service.