What is CVE-2026-18688?
CVE-2026-18688 is a vulnerability in MongoDB Server's aggregation framework where an authenticated user can trigger an out-of-bounds memory read via a specially crafted numeric parameter in an aggregation pipeline stage. This may lead to a server crash (Denial of Service) and potential exposure of sensitive information. Affected MongoDB Server users should urgently apply the relevant security patches.
Azərbaycanca: CVE-2026-18688 MongoDB Server-in aqreqasiya çərçivəsində autentifikasiya olunmuş istifadəçinin xüsusi hazırlanmış ədədi parametr vasitəsilə out-of-bounds memory read səhvinə səbəb olmasıdır. Bu, serverin çökməsinə (Denial of Service) və potensial məxfi məlumatların ifşasına yol aça bilər. MongoDB Server istifadəçiləri təcili olaraq təhlükəsizlik yeniləmələrini tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which MongoDB Server component is affected by CVE-2026-18688?
The vulnerability affects MongoDB Server's aggregation framework.
What outcomes can an authenticated attacker achieve by exploiting CVE-2026-18688?
It may lead to a server crash (Denial of Service) and potential exposure of sensitive information.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.