What is CVE-2026-18687?
This vulnerability exists in MongoDB Server's Queryable Encryption maintenance operation due to improper validation of request parameters against the encrypted field configuration. An authenticated user with readWrite privileges can send a specially crafted request to bypass intended restrictions. Upgrading MongoDB Server to the latest patched version is strongly recommended.
Azərbaycanca: Bu zəiflik MongoDB Server-də Queryable Encryption əməliyyatında parametrlərin düzgün yoxlanılmaması ilə bağlıdır. readWrite icazəsi olan autentifikasiya olunmuş istifadəçi xüsusi sorğu göndərərək şifrələnmiş kolleksiya konfiqurasiyasından kənar əməliyyat apara bilər. MongoDB serverini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which MongoDB Server operation does CVE-2026-18687 affect?
It affects the Queryable Encryption operation.
What privileges are required to exploit CVE-2026-18687?
An authenticated user with readWrite privileges is required.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.