CVE-2026-18691Patch(mongodb / mongodb)

LOWCVSS 9.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mongodb mongodb systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internal credential to be transmitted in a less-protected form, potentially allowing that credential to be recovered. If recovered, the credential could be used to authenticate as the internal superuser to nodes in the deployment.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-757

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mongodb

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
mongodb

2 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-12: 1Patch / Workaround · 2026-08-12: 1Technical Details · 2026-08-12: 108-12
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CCB Alert@CCBalert
    Patch

    Warning: Critical vulnerability in #MongoDB Server. CVE-2026-18691 CVSS: 9.0. An attacker with network access adjacent to the cluster can downgrade the authentication and potentially recover the superuser credential. More info: https://jira.mongodb.org/browse/SERVER-130264 #Patch #Patch #Patch

    Post summary

    The post highlights a critical authentication downgrade vulnerability (CVE-2026-18691) in MongoDB, provides technical details, and urges users to apply the available patch.

    01000344
    7.2K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appmongodbmongodb---
Appmongodbmongodb9.0.0--
Appmongodbmongodb9.0.0--
Appmongodbmongodb9.1.0--

Explore more