Denial of Service Vulnerability in MongoDB Server Affected by Unprivileged User Commands
CVE-2026-18707

5.3MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
11 August 2026

What is CVE-2026-18707?

An identified vulnerability in MongoDB Server allows an authenticated user, regardless of their assigned privileges, to craft a specific aggregation command that can lead to an unexpected termination of the server process. This behavior may result in denial of service conditions, significantly impacting the availability of the database service. To mitigate this issue, it is crucial for administrators to ensure appropriate access controls and monitor server command executions.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.8

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.