CVE-2026-18711: Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory Disclosure
An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference to be used after the underlying memory has been freed, when running certain queries against time-series collections. This could result in a server crash or disclosure of freed memory contents within query results.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18711?
The severity of CVE-2026-18711 is rated as high with a CVSS score of 7.1.
How do I fix CVE-2026-18711?
To fix CVE-2026-18711, update your MongoDB Server installation to the latest patched version.
What vulnerabilities are associated with CVE-2026-18711?
CVE-2026-18711 is associated with the Use-After-Free vulnerability that can lead to a denial of service and potential memory disclosure.
Who is affected by CVE-2026-18711?
CVE-2026-18711 affects authenticated users with read and write privileges in MongoDB Server.
What are the potential impacts of CVE-2026-18711?
The potential impacts of CVE-2026-18711 include server crashes and memory disclosures when specific queries are executed.