CVE-2026-18695: Improper Input Validation in MongoDB Timeseries Query Processing Leads to Denial of Service
An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user with write access to cause the server process to terminate unexpectedly, resulting in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18695?
The severity of CVE-2026-18695 is rated as medium with a score of 6.5.
How do I fix CVE-2026-18695?
To fix CVE-2026-18695, you should apply the latest security updates provided by MongoDB.
What type of vulnerability is CVE-2026-18695?
CVE-2026-18695 is categorized as an improper input validation vulnerability.
What impact does CVE-2026-18695 have on MongoDB?
CVE-2026-18695 can lead to a denial of service by allowing an authenticated user to terminate the server process.
Who is affected by CVE-2026-18695?
CVE-2026-18695 affects MongoDB servers handling time-series collections with a metaField, specifically those allowing authenticated users with write access.