CVE-2026-18687
Awaiting Analysis Awaiting Analysis - Queue

MongoDB Server Queryable Encryption Resource Exhaustion

Vulnerability report for CVE-2026-18687, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-28

Assigner: MongoDB, Inc.

Description

MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypted index data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-28
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mongodb mongodb_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-191 The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in MongoDB Server's Queryable Encryption feature involves improper validation of request parameters against encrypted field configurations. An authenticated user with readWrite privileges can exploit this to cause a server crash, excessive internal writes, resource exhaustion, or corruption of encrypted index data.

Detection Guidance

This vulnerability involves improper validation in MongoDB's Queryable Encryption maintenance operations. Detection requires monitoring for server crashes, excessive internal writes, or corruption of encrypted index data during maintenance tasks. Check MongoDB logs for unusual activity during encryption operations and verify that authenticated users with readWrite privileges are not submitting malformed requests targeting encrypted fields.

Impact Analysis

If exploited, this vulnerability could lead to denial of service due to server crashes, increased resource consumption, and potential data corruption in encrypted indexes. Attackers might gain unauthorized access to sensitive data or disrupt database operations.

Compliance Impact

This vulnerability could compromise data integrity and availability, violating GDPR's integrity and confidentiality principles or HIPAA's security requirements for protected health information. Non-compliance risks include legal penalties and reputational damage.

Mitigation Strategies

Update MongoDB Server to the latest patched version to address the improper parameter validation issue. Ensure only authenticated users with necessary privileges have access to readWrite operations. Monitor system resources for unusual activity or crashes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18687. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart