Certificate-Based Authentication Bypass in MongoDB Server
CVE-2026-18703
2.3LOW
What is CVE-2026-18703?
A security flaw in MongoDB Server permits an attacker with a valid client certificate and user account to bypass configured authentication restrictions. This flaw enables access through certificate-based authentication methods that the administrator explicitly intended to disable, potentially allowing unauthorized users to authenticate to the database.
Affected Version(s)
MongoDB Server 8.3.0 < 8.3.8