Memory Management Vulnerability in MongoDB Server by MongoDB Inc.
CVE-2026-18706

7.5HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
11 August 2026

What is CVE-2026-18706?

A vulnerability exists in MongoDB Server that affects the $graphLookup aggregation stage, potentially allowing authenticated users capable of issuing aggregation and memory-management commands to trigger the use of an internal reference after the associated memory has been freed. This flaw could lead to drastic outcomes such as server crashes or inadvertent execution of unintended code, thereby posing significant risks to data integrity and system stability.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.8

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.