JavaScript Scripting Engine Vulnerability in MongoDB Server
CVE-2026-18708

5.3MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
11 August 2026

What is CVE-2026-18708?

The MongoDB Server's JavaScript scripting engine contains a vulnerability that allows an authenticated user with write permissions to execute arbitrary code within the query scope of other users. This occurs when specially crafted stored values are processed during the internal maintenance cycle, which can lead to corruption of query results for other users and potential denial of service on shared database operations. The issue is confined to the scripting engine's execution environment, which does not expose sensitive database, filesystem, or network resources.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.8

MongoDB Server 8.0 < 8.0.29

MongoDB Server 7.0 < 7.0.40

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.