CVE-2026-18699
Awaiting Analysis Awaiting Analysis - Queue

Denial of Service in MongoDB Server via Query Planner

Vulnerability report for CVE-2026-18699, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-28

Assigner: MongoDB, Inc.

Description

An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index. This could result in a denial of service, affecting connected clients and in-flight operations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-28
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mongodb mongodb_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in MongoDB Server's query planner allows an authenticated user with read privileges to crash the server by submitting a specially crafted query against a collection with a text index. This causes a denial of service, disrupting connected clients and ongoing operations.

Detection Guidance

This vulnerability can be detected by monitoring MongoDB server logs for unexpected terminations during query processing. Check for crashes when text index queries are executed. Ensure MongoDB is updated to the latest patched version to prevent exploitation.

Impact Analysis

If exploited, this flaw could lead to unexpected server crashes, causing downtime for applications relying on MongoDB. This disrupts service availability and may result in data access issues for users and applications.

Compliance Impact

This denial of service could impact compliance by causing unplanned downtime, potentially violating availability requirements in GDPR and HIPAA. It may lead to disruptions in data access, affecting service level agreements and regulatory obligations.

Mitigation Strategies

Apply the latest MongoDB Server patch or upgrade to a version where this issue is resolved. Restrict authenticated user privileges to the minimum required for their roles. Monitor server logs for unexpected terminations or query failures.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18699. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart