JavaScript Scripting Engine Vulnerability in MongoDB Server
CVE-2026-18708
5.3MEDIUM
What is CVE-2026-18708?
The MongoDB Server's JavaScript scripting engine contains a vulnerability that allows an authenticated user with write permissions to execute arbitrary code within the query scope of other users. This occurs when specially crafted stored values are processed during the internal maintenance cycle, which can lead to corruption of query results for other users and potential denial of service on shared database operations. The issue is confined to the scripting engine's execution environment, which does not expose sensitive database, filesystem, or network resources.
Affected Version(s)
MongoDB Server 8.3.0 < 8.3.8
MongoDB Server 8.0 < 8.0.29
MongoDB Server 7.0 < 7.0.40