Denial of Service Vulnerability in MongoDB Server for Authenticated Users
CVE-2026-18699
6MEDIUM
What is CVE-2026-18699?
An issue has been identified in MongoDB Server's query planner that allows authenticated users with read-level privileges to craft specific queries that may cause the server process to terminate unexpectedly. This vulnerability can lead to a denial of service, affecting not only the server itself but also connected clients and ongoing operations. Users should review their query usage and apply necessary updates to mitigate potential risks.
Affected Version(s)
MongoDB Server 8.3.0 < 8.3.8
MongoDB Server 8.0 < 8.0.29
MongoDB Server 7.0 < 7.0.40