CVE-2026-18707
Awaiting Analysis Awaiting Analysis - Queue

Denial of Service in MongoDB Server via Aggregation Command

Vulnerability report for CVE-2026-18707, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-28

Assigner: MongoDB, Inc.

Description

An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-28
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mongodb mongodb_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in MongoDB Server allows an authenticated user, even with no privileges, to crash the server by sending a specially crafted aggregation command. This causes an unexpected termination of the server process, leading to a denial of service.

Detection Guidance

This vulnerability can be detected by monitoring for unexpected server terminations during aggregation operations. Check MongoDB logs for crashes or errors related to aggregation commands. Ensure your MongoDB version is up to date to avoid this issue.

Impact Analysis

The impact includes server unavailability, disrupted database operations, and potential data access issues during downtime. Users relying on MongoDB for critical services may experience service interruptions.

Compliance Impact

This vulnerability could lead to service disruptions, potentially violating availability requirements in GDPR and HIPAA. Downtime may impact data access and processing timelines, risking compliance with these regulations.

Mitigation Strategies

Update MongoDB Server to the latest patched version to address the denial of service issue caused by the aggregation command vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18707. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart