CVE-2026-18687: Improper Validation in MongoDB Queryable Encryption Maintenance Operation Leads to Denial of Service and Index Corruption
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypted index data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18687?
CVE-2026-18687 has a severity rating of high, with a CVSS score of 7.1.
How does CVE-2026-18687 affect MongoDB?
CVE-2026-18687 can lead to denial of service and index corruption by improper validation of request parameters.
Who can exploit CVE-2026-18687?
An authenticated user with readWrite privileges can exploit CVE-2026-18687 by submitting specially formed requests.
What are the implications of CVE-2026-18687?
The implications of CVE-2026-18687 include potential service disruptions and data integrity issues due to index corruption.
How can organizations mitigate CVE-2026-18687?
Organizations should apply the latest security updates and patches from MongoDB to mitigate CVE-2026-18687.