CVE-2026-18687Disclosure(mongodb / mongodb)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mongodb mongodb systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypted index data.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-191

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mongodb

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
mongodb

2 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-13: 1Patch / Workaround · 2026-08-13: 1Technical Details · 2026-08-13: 108-13
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-18687 - High severity DoS in MongoDB Queryable Encryption. Flawed validation lets authenticated users crash servers or corrupt encrypted indexes via crafted requests. CVSS 7.1. Unpatched—restrict access and monitor. #CVE #MongoDB #infosec https://www.valtersit.com/cve/CVE-2026-18687/ #infosec #CVE #infosec #SysAdmin #cybersecurity #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta

    Post summary

    The post announces CVE‑2026‑18687, a high‑severity DoS flaw in MongoDB Queryable Encryption, and advises restricting access and monitoring as mitigation.

    0000190
    1.0K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appmongodbmongodb---
Appmongodbmongodb9.0.0--
Appmongodbmongodb9.0.0--
Appmongodbmongodb9.1.0--

Explore more