CVE-2026-18707: Improper Input Validation in MongoDB Aggregation Command Handling Leads to Denial of Service
An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2026-18707?
CVE-2026-18707 refers to an improper input validation vulnerability in MongoDB that can lead to denial of service.
What is the severity of CVE-2026-18707?
The severity of CVE-2026-18707 is rated as medium with a score of 4.3.
How do I fix CVE-2026-18707?
To fix CVE-2026-18707, it is recommended to update MongoDB to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-18707?
Authenticated users of MongoDB, including those with no assigned privileges, are affected by CVE-2026-18707.
What can exploitation of CVE-2026-18707 lead to?
Exploitation of CVE-2026-18707 can result in the MongoDB server process terminating unexpectedly, causing a denial of service.