CVE-2026-18693: Out-of-Bounds Read/Write in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Memory Disclosure
An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data structure to become inconsistent through certain document insertions. A subsequent insert into the affected bucket could then result in the server accessing memory outside its intended bounds, potentially causing a server crash (denial of service), exposure of limited memory contents, or memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18693?
CVE-2026-18693 has a severity rating of 7.6, classified as high.
How do I fix CVE-2026-18693?
To address CVE-2026-18693, update your MongoDB Server to the latest patched version provided by MongoDB.
What effects can CVE-2026-18693 have on my system?
CVE-2026-18693 can lead to a denial of service and potential memory disclosure.
Who is affected by CVE-2026-18693?
Authenticated MongoDB users with write privileges to timeseries collections are affected by CVE-2026-18693.
What type of vulnerability is CVE-2026-18693?
CVE-2026-18693 is classified as an out-of-bounds read/write vulnerability.