CVE-2026-18703: Improper Enforcement of Authentication Mechanism Restrictions in MongoDB Server Allows Use of Disabled Authentication Method
An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to restrict authentication to other mechanisms. This could allow authentication through a method the administrator intended to disable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18703?
CVE-2026-18703 has a medium severity rating of 4.2.
How do I fix CVE-2026-18703?
To mitigate CVE-2026-18703, ensure that authentication mechanisms are properly configured and disable any unwanted authentication methods.
What are the potential impacts of CVE-2026-18703?
CVE-2026-18703 may allow unauthorized access to the MongoDB server through a disabled authentication method if proper restrictions are not enforced.
Who is affected by CVE-2026-18703?
Any MongoDB Server installation that has restricted authentication configurations but allows certificate-based authentication can be affected by CVE-2026-18703.
What should I do if I suspect exploitation of CVE-2026-18703?
If you suspect exploitation of CVE-2026-18703, immediately review authentication configurations and monitor server access logs for suspicious activity.