Denial of Service Vulnerability in MongoDB Server Affected by Unprivileged User Commands
CVE-2026-18707
5.3MEDIUM
What is CVE-2026-18707?
An identified vulnerability in MongoDB Server allows an authenticated user, regardless of their assigned privileges, to craft a specific aggregation command that can lead to an unexpected termination of the server process. This behavior may result in denial of service conditions, significantly impacting the availability of the database service. To mitigate this issue, it is crucial for administrators to ensure appropriate access controls and monitor server command executions.
Affected Version(s)
MongoDB Server 8.3.0 < 8.3.8