CVE-2026-18695
Awaiting Analysis Awaiting Analysis - Queue

Denial of Service in MongoDB Server via Time-Series Query

Vulnerability report for CVE-2026-18695, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-28

Assigner: MongoDB, Inc.

Description

An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user with write access to cause the server process to terminate unexpectedly, resulting in a denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-28
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mongodb mongodb_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in MongoDB Server where an authenticated user with write access can craft specific query predicates against time-series collections with a metaField. This causes the server process to crash unexpectedly, leading to a denial of service.

Detection Guidance

Detection of this vulnerability requires monitoring for unexpected server terminations in MongoDB instances hosting time-series collections with a metaField. Check MongoDB logs for crash events or core dumps. Ensure your MongoDB version is updated to the latest patch to mitigate this issue.

Impact Analysis

If exploited, this vulnerability could disrupt database operations by crashing the MongoDB server, leading to service unavailability for all users relying on that instance.

Compliance Impact

This vulnerability causes a denial of service by crashing the MongoDB server process, which could lead to data unavailability. For GDPR, this may impact data access rights and availability requirements. For HIPAA, it could disrupt access to protected health information, potentially violating integrity and availability standards.

Mitigation Strategies

Update MongoDB Server to the latest patched version to address the issue with time-series collections and query predicates. Ensure only authenticated users with necessary permissions have write access to prevent unauthorized exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18695. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart