CVE-2026-18699: Improper Input Validation in MongoDB Query Planner Leads to Denial of Service
An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index. This could result in a denial of service, affecting connected clients and in-flight operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18699?
The severity of CVE-2026-18699 is medium, rated at 6.5.
What does CVE-2026-18699 affect?
CVE-2026-18699 affects MongoDB Server and can lead to a denial of service.
How do I fix CVE-2026-18699?
To fix CVE-2026-18699, update to the latest version of MongoDB Server that addresses this vulnerability.
What is the impact of CVE-2026-18699?
The impact of CVE-2026-18699 is that it allows an authenticated user to terminate the server process unexpectedly, resulting in a denial of service.
Who is affected by CVE-2026-18699?
CVE-2026-18699 affects MongoDB users with read-level privileges who can submit specially formed queries.