Out-of-Bounds Memory Read in MongoDB Server's Aggregation Framework
CVE-2026-18688
7.1HIGH
What is CVE-2026-18688?
An issue within the aggregation framework of MongoDB Server allows an authenticated user to exploit a specially crafted numeric parameter, leading to an out-of-bounds memory read. This flaw has the potential to result in a server crash through denial of service and may inadvertently reveal a limited amount of memory contents, posing a risk to data integrity.
Affected Version(s)
MongoDB Server 8.3.0 < 8.3.8
MongoDB Server 8.0 < 8.0.29
MongoDB Server 7.0 < 7.0.40