MongoDB Server Vulnerability in Queryable Encryption Maintenance Operations
CVE-2026-18687

7.1HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
11 August 2026

What is CVE-2026-18687?

An issue in MongoDB Server's Queryable Encryption maintenance operation allows authenticated users with readWrite privileges to exploit improperly validated request parameters. By crafting a malicious request, a user can trigger a server crash or cause excessive internal writes. This vulnerability can lead to resource exhaustion and potential corruption of encrypted index data, highlighting critical weaknesses in the handling of encrypted field configurations.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.8

MongoDB Server 8.0 < 8.0.29

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.